Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-50269

Gravedad CVSS v4.0:
BAJA
Tipo:
CWE-93 Neutralización incorrecta de secuencias de retornos de carro y saltos de linea (CRLF)
Fecha de publicación:
22/06/2026
Última modificación:
26/06/2026

Descripción

*** Pendiente de traducción *** AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled input included into multipart/payload headers can be used to modify a request to inject additional headers or similar. In the unlikely situation that an application is passing user-controlled strings into MultipartWriter.append(headers=...) or Payload.headers, then an attacker may be able to modify the request to inject headers or change the contents of the request. This vulnerability is fixed in 3.14.0.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:aiohttp:aiohttp:*:*:*:*:*:*:*:* 3.14.0 (excluyendo)