7.3
CVE-2026-34993
- EPSS 0.18%
- Veröffentlicht 02.06.2026 18:29:15
- Zuletzt bearbeitet 04.09.2026 13:19:29
- Erkennungen
AIOHTTP Vulnerable to Deserialization of Untrusted Data
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be doing so with the user's own data, so this is unlikely to affect many applications. Version 3.14.0 patches the issue. If an application does allow attacker controlled files to be loaded, a workaround on older releases would be to sanitize the files before loading.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.076 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.3 | 1.3 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
|
| security-advisories@github.com | 6.4 | 0.6 | 5.3 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:H/A:L
|
| 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | 7.2 | 0.6 | 6 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
https://github.com/aio-libs/aiohttp/commit/dcf40f30637e8752c76781cf6703b5a236749a00
https://bugzilla.redhat.com/show_bug.cgi?id=2484099
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34993.json
https://access.redhat.com/errata/RHSA-2026:24977
https://access.redhat.com/errata/RHSA-2026:34456
https://github.com/aio-libs/aiohttp/security/advisories/GHSA-jg22-mg44-37j8
https://access.redhat.com/security/cve/CVE-2026-34993
https://access.redhat.com/errata/RHSA-2026:37275
https://access.redhat.com/errata/RHSA-2026:42644
https://access.redhat.com/errata/RHSA-2026:43038
https://access.redhat.com/errata/RHSA-2026:50340
https://access.redhat.com/errata/RHSA-2026:50357
https://access.redhat.com/errata/RHSA-2026:50319
https://access.redhat.com/errata/RHSA-2026:50336
https://access.redhat.com/errata/RHSA-2026:50479
https://access.redhat.com/errata/RHSA-2026:54760
https://access.redhat.com/errata/RHSA-2026:59135
https://access.redhat.com/errata/RHSA-2026:59136
https://access.redhat.com/errata/RHSA-2026:59518
https://access.redhat.com/errata/RHSA-2026:60520
https://access.redhat.com/errata/RHSA-2026:62336
https://access.redhat.com/errata/RHSA-2026:62335
https://access.redhat.com/errata/RHSA-2026:63387
https://access.redhat.com/errata/RHSA-2026:63385
https://access.redhat.com/errata/RHSA-2026:63386
https://access.redhat.com/errata/RHSA-2026:63327