Project Subscriptions
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jg22-mg44-37j8 | AIOHTTP is Vulnerable to Deserialization of Untrusted Data |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 05 Jun 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aiohttp
Aiohttp aiohttp |
|
| CPEs | cpe:2.3:a:aiohttp:aiohttp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aiohttp
Aiohttp aiohttp |
Wed, 03 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Jun 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aio-libs
Aio-libs aiohttp |
|
| Vendors & Products |
Aio-libs
Aio-libs aiohttp |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be doing so with the user's own data, so this is unlikely to affect many applications. Version 3.14.0 patches the issue. If an application does allow attacker controlled files to be loaded, a workaround on older releases would be to sanitize the files before loading. | |
| Title | AIOHTTP Vulnerable to Deserialization of Untrusted Data | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-03T14:08:22.635Z
Reserved: 2026-03-31T19:38:31.618Z
Link: CVE-2026-34993
Updated: 2026-06-03T13:59:40.405Z
Status : Analyzed
Published: 2026-06-02T20:16:34.857
Modified: 2026-06-05T13:44:31.720
Link: CVE-2026-34993
No data.
OpenCVE Enrichment
Updated: 2026-06-03T04:45:25Z
Github GHSA