{"id":"CVE-2026-34514","aliases":["GHSA-2vrm-gr82-f7m5","PYSEC-2026-2096"],"title":"AIOHTTP has CRLF injection through multipart part content type header construction","summary":"AIOHTTP has CRLF injection through multipart part content type header construction","severity":"low","vendor":"aiohttp","product":"aiohttp","ecosystem":"pip","affected":["aiohttp < 3.13.4"],"patched":["aiohttp 3.13.4"],"published":"2026-04-01","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:42.288164171Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-2vrm-gr82-f7m5","references":[{"url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-2vrm-gr82-f7m5"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34514"},{"url":"https://github.com/aio-libs/aiohttp/commit/9a6ada97e2c6cf1ce31727c6c9fcea17c21f6f06"},{"url":"https://github.com/aio-libs/aiohttp"},{"url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4"}],"tags":["osv","pip"],"epss":0.00315,"epssPercentile":0.24668,"ingestedAt":"2026-07-13T18:57:51.530Z","slug":"CVE-2026-34514","body":"## Overview\n\n### Summary\n\nAn attacker who controls the `content_type` parameter in aiohttp could use this to inject extra headers or similar exploits.\n\n### Impact\n\nIf an application allows untrusted data to be used for the multipart `content_type` parameter when constructing a request, an attacker may be able to manipulate the request to send something other than what the developer intended.\n\n-----\n\nPatch: https://github.com/aio-libs/aiohttp/commit/9a6ada97e2c6cf1ce31727c6c9fcea17c21f6f06\n\n## Affected packages\n\n- `aiohttp < 3.13.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `aiohttp 3.13.4`","depth":"sunlit","depthScore":14,"depthScoreParts":{"impact":13.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}