CVE-2026-34514
Received Received - Intake
HTTP Header Injection Vulnerability in AIOHTTP Before

Publication date: 2026-04-01

Last updated on: 2026-04-15

Assigner: GitHub, Inc.

Description
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the content_type parameter in aiohttp could use this to inject extra headers or similar exploits. This issue has been patched in version 3.13.4.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-04-01
Last Modified
2026-04-15
Generated
2026-06-16
AI Q&A
2026-04-02
EPSS Evaluated
2026-06-15
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
aiohttp aiohttp to 3.13.4 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-113 The product receives data from an HTTP agent/component (e.g., web server, proxy, browser, etc.), but it does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Mitigation Strategies

To mitigate this vulnerability, you should upgrade aiohttp to version 3.13.4 or later, where the issue has been patched.

Executive Summary

This vulnerability exists in the AIOHTTP framework, which is an asynchronous HTTP client/server framework for asyncio and Python. Before version 3.13.4, an attacker who could control the content_type parameter in aiohttp could exploit this to inject extra HTTP headers or perform similar attacks.

The issue was fixed in version 3.13.4 of aiohttp.

Impact Analysis

If an attacker can control the content_type parameter, they may be able to inject additional HTTP headers or carry out similar exploits. This could potentially lead to unexpected behavior in the application, such as security bypasses or manipulation of HTTP requests and responses.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-34514. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart