[pkg-vuln] CVE-2026-47265 in aiohttp@3.13.5 #520
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Severity: MEDIUM
Package:
aiohttp@3.13.5Fixed in:
3.14.0AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the
cookiesparameter on requests are sent after following a cross-origin redirect. If a developer uses thecookiesparameter on a per-request basis then sensitive data might be leaked to an attacker if they manage to control a redirect. Version 3.14.0 patches the issue. If unable to upgrade, using aCookieheader in theheadersparameter is not vulnerable.Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-47265
Not exploitable here. CVE-2026-47265 leaks per-request
cookies=across cross-origin redirects; the storage SDKs authenticate with signed headers, not cookies, and no code passescookies=. aiohttp enters this stack only as a transitive client dependency of the fsspec cloud-storage backends (s3fs / gcsfs / adlfs via aiobotocore —uv tree --invert --package aiohttp), talking to fixed, trusted storage endpoints. Nothing in the repo runs an aiohttp server or imports aiohttp directly.Bumped anyway (defense in depth):
aiohttp3.13.5 → 3.14.1 in65c31cf88f(uv.lock + pkg-manifest; pyproject floor raised for direct deps). Advisory link is in the issue body.