CVE-2026-34514

Severity CVSS v4.0:
LOW
Type:
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
Publication date:
01/04/2026
Last modified:
15/04/2026

Description

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the content_type parameter in aiohttp could use this to inject extra headers or similar exploits. This issue has been patched in version 3.13.4.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:aiohttp:aiohttp:*:*:*:*:*:*:*:* 3.13.4 (excluding)