Multiple Host Headers Vulnerability in AIOHTTP by Aio-libs
CVE-2026-34525

6.3MEDIUM

Key Information:

Vendor

Aio-libs

Status
Vendor
CVE Published:
1 April 2026

What is CVE-2026-34525?

The AIOHTTP framework prior to version 3.13.4 permitted multiple Host headers, potentially facilitating malicious actions such as response splitting or cache poisoning. This flaw compromises the integrity of HTTP requests, allowing attackers to manipulate how servers handle requests. This issue has been rectified in version 3.13.4 with appropriate checks to restrict the number of Host headers to one.

Affected Version(s)

aiohttp < 3.13.4

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.