CVE-2026-54276

EUVD-2026-38313
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This likely requires an open redirect vulnerability or similar on the target domain for an attacker to be able to execute. Further, the attacker is only receiving the digest, so should only be able to extract the user's credentials if the cryptography is weak or there is some kind of password reuse. This vulnerability is fixed in 3.14.1.
Open Redirect
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 7.52%
Affected Products (NVD)
VendorProductVersion
aiohttpaiohttp
𝑥
< 3.14.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
python-aiohttp
bookworm
3.8.4-1+deb12u1
fixed
bookworm (security)
3.8.4-1+deb12u1
fixed
bullseye
3.7.4-1
fixed
bullseye (security)
3.7.4-1+deb11u2
fixed
forky
3.14.1-4
fixed
sid
3.14.1-4
fixed
trixie
3.11.16-1+deb13u1
fixed
trixie (security)
3.11.16-1+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-aiohttp
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage