Logo
vulnerabilityCVE-2026-47265
Name
CVE-2026-47265
Source
NVD ( link)Debian ( link)
Description
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the `cookies` parameter on requests are sent after following a cross-origin redirect. If a developer uses the `cookies` parameter on a per-request basis then sensitive data might be leaked to an attacker if they manage to control a redirect. Version 3.14.0 patches the issue. If unable to upgrade, using a `Cookie` header in the `headers` parameter is not vulnerable.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
python-aiohttp
Exploitable

Vulnerability Ratings#


6.6
CVSSv4
7.5
CVSSv31
NaN
other

Others affected component#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.12.14
Exploitable