CVE-2026-34514

Aliases:GHSA-2vrm-gr82-f7m5PYSEC-2026-2096UBUNTU-CVE-2026-34514DEBIAN-CVE-2026-34514CGA-29pj-g63x-9f4rCGA-2jp8-cp2h-vffgCGA-46mc-8hq8-7jjfCGA-72h2-jv7g-9m6vCGA-7g46-fw76-9wg3CGA-9cqw-73xx-5g44CGA-9gwq-52hj-rr3qCGA-9w9f-94xv-456jCGA-9x63-6qqw-fvvfCGA-ccvw-jr58-3c52CGA-f3gg-c25g-4g96CGA-jqcc-ww57-v697CGA-27jg-g77c-gw9fCGA-2h2q-jvhx-qcg6CGA-2qgg-crx4-763jCGA-32gp-4vcw-4pxcCGA-36wr-8fm4-mr9mCGA-3fjj-46gj-qh5xCGA-3fmv-gc6x-q669CGA-3p69-73pp-7v7gCGA-3qjr-gp7x-45qpCGA-4jm3-w5qp-5gj5CGA-4pr4-7x34-8gjvCGA-533x-974f-g73cCGA-69vr-rcv7-v9v7CGA-6j76-j226-jxgpCGA-6jh2-w84m-w8f2CGA-7pvq-hfr8-7f2vCGA-7v86-98rh-7728CGA-8rj3-p9w2-gppjCGA-95rm-hvv2-96h2CGA-9p96-c7v3-6c8fCGA-9pv6-629f-v955CGA-c6w8-h8q4-7p9gCGA-cwp2-rxj4-2h57CGA-cwpm-w68v-v45hCGA-g6xq-j7mw-3366CGA-g77x-fmhp-h874CGA-gr3f-7mvp-pmjqCGA-gw74-jv3g-q4r6CGA-h83q-77q9-vrggCGA-hjrq-c2fh-m4rwCGA-hmxg-j9gv-qv3cCGA-hp9v-qfx3-gggrCGA-mj8g-f8hw-g57hCGA-p9qw-hqc4-f9pgCGA-pjvm-gqwg-x44gCGA-px62-3m23-jjqfCGA-qj59-x56j-cgj6CGA-qpv7-5733-7q7wCGA-qrp4-r388-rqqmCGA-r2qr-cv57-rg57CGA-r6x4-3hg6-w856CGA-rjx3-qqfq-mpm2CGA-vqcx-fv55-q935CGA-vrmp-xqh7-33hmCGA-vwcq-g673-p6wrCGA-w4pj-cw3q-8mffCGA-w822-9rvj-qj9hCGA-wqrx-h399-rv7f
Analyzed
Published: 01 Apr 2026, 20:09
Last modified:02 Apr 2026, 14:07

Vulnerability Summary

Overall Risk (default)
low
21/100
CVSS Score
5.3 MEDIUM
v3.1 (nvd)
EPSS Score
0.32% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

01 Apr 2026, 20:09
Published
Vulnerability first disclosed
02 Apr 2026, 14:07
Last Modified
Vulnerability information updated

Description

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the content_type parameter in aiohttp could use this to inject extra headers or similar exploits. This issue has been patched in version 3.13.4.

CVSS Metrics

  • v4.0LOWScore: 2.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U
  • v4.0LOWScore: 2.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

EPSS Trends

Current EPSS score: 0.32% Percentile: 25%

Techniques & Countermeasures

  • CWE-113Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')

    The product receives data from an HTTP agent/component (e.g., web server, proxy, browser, etc.), but it does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers.

Affected Systems

  • aio-libsaiohttp

    < 3.13.4

  • aiohttpaiohttp

    < 3.13.4

  • chainguardairflow-2

    < 2.11.2-r5

  • chainguardairflow-3

    < 3.1.8-r11 | < 3.2.1-r0

  • chainguardairflow-core-2

    < 2.11.2-r3

  • chainguardauthentik-2025.12

    < 2025.12.4-r3

  • chainguardauthentik-2026.2

    < 2026.2.1-r3

  • chainguardauthentik-fips-2025.12

    < 2025.12.4-r3

  • chainguardauthentik-fips-2026.2

    < 2026.2.1-r3

  • chainguardawx

    < 24.6.1-r33

  • chainguardcheckov

    < 3.2.517-r0

  • chainguarddask-kubernetes

    < 2026.3.0-r3

  • chainguarddatahub-ingestion

    < 1.6.0-r1

  • chainguarddatahub-ingestion-fips

    < 1.5.0.1-r1

  • chainguardkeep-api

    < 0.51.0-r2

  • chainguardkeep-api-fips

    < 0.51.0-r2

  • chainguardkserve-storage-controller

    < 0.17.0-r2

  • chainguardkubeflow-pipelines-visualization-server

    < 2.16.0-r4

  • chainguardlitellm

    < 1.82.3.0-r3

  • chainguardmetaflow-service

    < 2.5.0-r10

  • chainguardmetaflow-service-fips

    < 2.5.0-r2

  • chainguardopen-webui

    < 0.8.12-r3

  • chainguardpy3-cassandra-medusa

    < 0.27.1-r2

  • chainguardpy3.13-scanner-test-libraries-aiohttp

    < 0.0.1-r3

  • chainguardrequest-1276

    < 0.27.1-r2

  • chainguardtext-generation-inference

    < 3.3.7-r10

  • chainguardtritonserver-backend-vllm-cuda-12.9

    < 25.9.0_git20260318-r1

  • chainguardtritonserver-backend-vllm-cuda-13.0

    < 25.11-r3

  • wolfiairflow-3

    < 3.1.8-r11 | < 3.2.1-r0

  • wolficheckov

    < 3.2.517-r0

  • wolfidask-kubernetes

    < 2026.3.0-r3

  • wolfikserve-storage-controller

    < 0.17.0-r2

  • wolfikubeflow-pipelines-visualization-server

    < 2.16.0-r4

  • wolfiopen-webui

    < 0.8.12-r3

  • wolfipy3-cassandra-medusa

    < 0.27.1-r2

  • debianpython-aiohttp

    < 3.7.4-1+deb11u2 | all | all | < 3.13.5-1

  • ubuntupython-aiohttp

    < 0.20.2-1ubuntu0.1~esm1 | < 3.0.1-1ubuntu0.1~esm7 | < 3.8.1-4ubuntu0.2+esm3 | < 3.9.1-1ubuntu0.1+esm3 | all | < 3.13.3-3ubuntu1+esm1

  • PyPIaiohttp

    < 3.13.4

References (10)