CVE-2026-34993
MEDIUM
6,4
Source: [email protected]
Attack Vector: local
Attack Complexity: high
Privileges Required: high
User Interaction: required
Scope: changed
Confidentiality: low
Integrity: high
Availability: low
Description
AI Translation Available
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be doing so with the user's own data, so this is unlikely to affect many applications. Version 3.14.0 patches the issue. If an application does allow attacker controlled files to be loaded, a workaround on older releases would be to sanitize the files before loading.
502
Deserialization of Untrusted Data
DraftCommon Consequences
Security Scopes Affected:
Integrity
Availability
Other
Potential Impacts:
Modify Application Data
Unexpected State
Dos: Resource Consumption (Cpu)
Varies By Context
Applicable Platforms
Languages:
Java, Ruby, PHP, Python, JavaScript
Technologies:
Not Technology-Specific, ICS/OT, AI/ML
https://github.com/aio-libs/aiohttp/commit/dcf40f30637e8752c76781cf6703b5a23674…
https://github.com/aio-libs/aiohttp/security/advisories/GHSA-jg22-mg44-37j8