Multiple Host Headers Vulnerability in AIOHTTP by Aio-libs
CVE-2026-34525
6.3MEDIUM
What is CVE-2026-34525?
The AIOHTTP framework prior to version 3.13.4 permitted multiple Host headers, potentially facilitating malicious actions such as response splitting or cache poisoning. This flaw compromises the integrity of HTTP requests, allowing attackers to manipulate how servers handle requests. This issue has been rectified in version 3.13.4 with appropriate checks to restrict the number of Host headers to one.
Affected Version(s)
aiohttp < 3.13.4
