[pkg-vuln] CVE-2026-34525 in aiohttp@3.13.3 #321
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Severity: MEDIUM
Package:
aiohttp@3.13.3Fixed in:
3.13.4AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4.
Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-34525