CVE-2026-54279
LOW
1.3
CVSS 4.0
Description
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status. This vulnerability is fixed in 3.14.1.
Metadata
Severity & Metrics
1.3
LOW CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:U
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| aio-libs | aiohttp | — | < 3.14.1 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-665 | cna | CWE-665: Improper Initialization |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 1.3 | LOW | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:U |
References (2)
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-2fqr-mr3j-6wp8 https://github.com/aio-libs/aiohttp/security/advisories/GHSA-2fqr-mr3j-6wp8
- https://github.com/aio-libs/aiohttp/commit/a329a7aacad5284f087af36103aff778746da0f2 https://github.com/aio-libs/aiohttp/commit/a329a7aacad5284f087af36103aff778746da0f2