Asynchronous HTTP Client Framework Vulnerability in AIOHTTP by aio-libs
CVE-2026-34519
2.7LOW
What is CVE-2026-34519?
A vulnerability exists in AIOHTTP, an asynchronous HTTP framework for Python, which allows an attacker controlling the 'reason' parameter in Response creation to inject unauthorized headers or carry out similar exploits. This vulnerability has been resolved in version 3.13.4, thus users are advised to update their AIOHTTP installations to this version or later to mitigate the risk.
Affected Version(s)
aiohttp < 3.13.4
