Project Subscriptions
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hg6j-4rv6-33pg | AIOHTTP is vulnerable to cross-origin redirect with per-request cookies |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 05 Jun 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aiohttp
Aiohttp aiohttp |
|
| CPEs | cpe:2.3:a:aiohttp:aiohttp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aiohttp
Aiohttp aiohttp |
|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 04 Jun 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-201 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Wed, 03 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Jun 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aio-libs
Aio-libs aiohttp |
|
| Vendors & Products |
Aio-libs
Aio-libs aiohttp |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the `cookies` parameter on requests are sent after following a cross-origin redirect. If a developer uses the `cookies` parameter on a per-request basis then sensitive data might be leaked to an attacker if they manage to control a redirect. Version 3.14.0 patches the issue. If unable to upgrade, using a `Cookie` header in the `headers` parameter is not vulnerable. | |
| Title | AIOHTTP vulnerable to cross-origin redirect with per-request cookies | |
| Weaknesses | CWE-346 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-03T12:48:54.358Z
Reserved: 2026-05-18T23:03:37.229Z
Link: CVE-2026-47265
Updated: 2026-06-03T12:48:50.920Z
Status : Analyzed
Published: 2026-06-02T20:16:37.903
Modified: 2026-06-05T13:39:20.167
Link: CVE-2026-47265
OpenCVE Enrichment
Updated: 2026-06-04T13:30:06Z
Github GHSA