Bypass of TLS SNI Check in AIOHTTP Framework by Aio-libs
CVE-2026-54275

2.7LOW

Key Information:

Vendor

Aio-libs

Status
Vendor
CVE Published:
22 June 2026

What is CVE-2026-54275?

AIOHTTP, an asynchronous HTTP client/server framework for Python, is affected by a vulnerability that allows the TLS server_hostname SNI check to be bypassed. When reusing existing connections, applications making multiple requests to the same domain with differing per-request server_hostname parameters may unintentionally succeed in calls that should have been rejected. This flaw can lead to potential misuse, undermining the protection that TLS is designed to provide. The issue has been rectified in version 3.14.1.

Affected Version(s)

aiohttp < 3.14.1

References

CVSS V4

Score:
2.7
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.