CVE-2026-34518
ADVISORY - githubSummary
Summary
When following redirects to a different origin, aiohttp drops the Authorization header, but retains the Cookie and Proxy-Authorization headers.
Impact
The Cookie and Proxy-Authorizations headers could contain sensitive information which may be leaked to an unintended party after following a redirect.
Patch: https://github.com/aio-libs/aiohttp/commit/5351c980dcec7ad385730efdf4e1f4338b24fdb6
EPSS Score: 0.0004 (0.122)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Exposure of Sensitive Information to an Unauthorized Actor
ADVISORY - github
Exposure of Sensitive Information to an Unauthorized Actor
ADVISORY - redhat
Exposure of Sensitive System Information to an Unauthorized Control Sphere
NIST
CREATED
UPDATED
ADVISORY IDCVE-2026-34518
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
2.7lowGitHub
CREATED
UPDATED
ADVISORY IDGHSA-966j-vmvw-g2g9
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
2.7lowDebian
CREATED
UPDATED
ADVISORY IDCVE-2026-34518
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
Ubuntu
CREATED
UPDATED
ADVISORY IDCVE-2026-34518
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AmediumRed Hat
CREATED
UPDATED
ADVISORY IDCVE-2026-34518
EXPLOITABILITY SCORE
2.2
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
3.7lowChainguard
CREATED
UPDATED
ADVISORY ID
CGA-c2p6-689m-2c8f
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-