Description
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-c427-h43c-vf67 | AIOHTTP accepts duplicate Host headers |
References
History
Thu, 02 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4. | |
| Title | AIOHTTP: Duplicate Host header accepted | |
| Weaknesses | CWE-20 CWE-444 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-01T20:28:46.652Z
Reserved: 2026-03-30T16:03:31.048Z
Link: CVE-2026-34525
No data.
Status : Received
Published: 2026-04-01T21:17:00.490
Modified: 2026-04-01T21:17:00.490
Link: CVE-2026-34525
OpenCVE Enrichment
No data.
Github GHSA