[pkg-vuln] CVE-2026-47265 in aiohttp@3.13.5 #520

Closed
opened 2026-07-10 01:31:25 +00:00 by kert · 1 comment
Owner

Severity: MEDIUM
Package: aiohttp @ 3.13.5
Fixed in: 3.14.0

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the cookies parameter on requests are sent after following a cross-origin redirect. If a developer uses the cookies parameter on a per-request basis then sensitive data might be leaked to an attacker if they manage to control a redirect. Version 3.14.0 patches the issue. If unable to upgrade, using a Cookie header in the headers parameter is not vulnerable.

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-47265

**Severity:** MEDIUM **Package:** `aiohttp` @ `3.13.5` **Fixed in:** `3.14.0` AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the `cookies` parameter on requests are sent after following a cross-origin redirect. If a developer uses the `cookies` parameter on a per-request basis then sensitive data might be leaked to an attacker if they manage to control a redirect. Version 3.14.0 patches the issue. If unable to upgrade, using a `Cookie` header in the `headers` parameter is not vulnerable. **Reference:** https://nvd.nist.gov/vuln/detail/CVE-2026-47265
kert added this to the P21: Package Supply Chain — inventory, mirrors, drift, vuln scanning milestone 2026-07-10 01:31:25 +00:00
kert added the qualityci labels 2026-07-10 01:31:25 +00:00
Author
Owner

Not exploitable here. CVE-2026-47265 leaks per-request cookies= across cross-origin redirects; the storage SDKs authenticate with signed headers, not cookies, and no code passes cookies=. aiohttp enters this stack only as a transitive client dependency of the fsspec cloud-storage backends (s3fs / gcsfs / adlfs via aiobotocore — uv tree --invert --package aiohttp), talking to fixed, trusted storage endpoints. Nothing in the repo runs an aiohttp server or imports aiohttp directly.

Bumped anyway (defense in depth): aiohttp 3.13.5 → 3.14.1 in 65c31cf88f (uv.lock + pkg-manifest; pyproject floor raised for direct deps). Advisory link is in the issue body.

**Not exploitable here.** CVE-2026-47265 leaks per-request `cookies=` across cross-origin redirects; the storage SDKs authenticate with signed headers, not cookies, and no code passes `cookies=`. aiohttp enters this stack only as a transitive **client** dependency of the fsspec cloud-storage backends (s3fs / gcsfs / adlfs via aiobotocore — `uv tree --invert --package aiohttp`), talking to fixed, trusted storage endpoints. Nothing in the repo runs an aiohttp **server** or imports aiohttp directly. **Bumped anyway** (defense in depth): `aiohttp` 3.13.5 → 3.14.1 in https://git.fhirworx.io/homelab/stack/commit/65c31cf88fd8de552a006859159790de468403fb (uv.lock + pkg-manifest; pyproject floor raised for direct deps). Advisory link is in the issue body.
kert closed this issue 2026-07-10 17:18:57 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: homelab/stack#520