Description
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in response headers. This issue has been patched in version 3.13.4.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-63hf-3vf5-4wqf | AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass |
References
History
Thu, 02 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1286 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in response headers. This issue has been patched in version 3.13.4. | |
| Title | AIOHTTP: C parser (llhttp) accepts null bytes and control characters in response header values - header injection / security bypass | |
| Weaknesses | CWE-113 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-01T20:27:48.350Z
Reserved: 2026-03-30T16:03:31.047Z
Link: CVE-2026-34520
No data.
Status : Received
Published: 2026-04-01T21:17:00.333
Modified: 2026-04-01T21:17:00.333
Link: CVE-2026-34520
OpenCVE Enrichment
No data.
Github GHSA