CVE-2026-34520
Received Received - Intake
Null Byte Injection in AIOHTTP C Parser Allows Header Manipulation

Publication date: 2026-04-01

Last updated on: 2026-04-16

Assigner: GitHub, Inc.

Description
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in response headers. This issue has been patched in version 3.13.4.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-04-01
Last Modified
2026-04-16
Generated
2026-06-16
AI Q&A
2026-04-02
EPSS Evaluated
2026-06-15
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
aiohttp aiohttp to 3.13.4 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-113 The product receives data from an HTTP agent/component (e.g., web server, proxy, browser, etc.), but it does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability affects AIOHTTP, an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser used by AIOHTTP accepted null bytes and control characters in response headers, which is not expected behavior. This issue was fixed in version 3.13.4.

Impact Analysis

Accepting null bytes and control characters in response headers can lead to unexpected behavior in applications using AIOHTTP. This may cause security issues such as header injection or improper parsing of HTTP responses, potentially leading to information disclosure or other security risks.

Mitigation Strategies

To mitigate this vulnerability, upgrade the AIOHTTP package to version 3.13.4 or later, where the issue with the C parser accepting null bytes and control characters in response headers has been patched.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-34520. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart