CVE-2026-34520
Severity CVSS v4.0:
LOW
Type:
CWE-113
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
Publication date:
01/04/2026
Last modified:
04/04/2026
Description
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in response headers. This issue has been patched in version 3.13.4.
Impact
Base Score 4.0
2.70
Severity 4.0
LOW
Base Score 3.x
9.10
Severity 3.x
CRITICAL



