Security Advisory

CVE-2026-50269

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-22 16:30:55
Last updated 2026-06-22 17:22:34
Assigner GitHub_M
CVSS score 2.7
State PUBLISHED

Description

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled input included into multipart/payload headers can be used to modify a request to inject additional headers or similar. In the unlikely situation that an application is passing user-controlled strings into MultipartWriter.append(headers=...) or Payload.headers, then an attacker may be able to modify the request to inject headers or change the contents of the request. This vulnerability is fixed in 3.14.0.