CVE-2026-34519

MEDIUM WAF: High
CVSS 5.3 Published: 2026-04-01
CWE-113

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the reason parameter when creating a Response may be able to inject extra headers or similar exploits. This issue has been patched in version 3.13.4.

WAF Coverage Analysis

HTTP Response Splitting High WAF Coverage

OWASP: A03:2021 Injection

921xxx - Protocol Attack

Affected Software

VendorProductVersion
aiohttpaiohttpup to 3.13.4

References

Back to CVE Database