{"id":"CVE-2026-34993","title":"aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() (CVE-2026-34993)","summary":"A flaw was found in AIOHTTP, an asynchronous HTTP client/server framework for asyncio and Python. An attacker could exploit this vulnerability by providing untrusted input to the `CookieJar.load()` function. This could potentially lead to …","severity":"high","cvss":7.2,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-502","vendor":"Red Hat","product":"Red Hat OpenShift AI 3.4","affected":["exploit_intelligence","openshift_lightspeed","ai_inference_server","ansible_automation_platform 2","enterprise_linux_ai_rhel_ai 3","openshift_ai_rhoai","satellite 6","update_infrastructure_4_for_cloud_providers","ansible_automation_platform_2_5_for_rhel 8","satellite_6_16_for_rhel 8","ansible_automation_platform_2_5_for_rhel 9","ansible_automation_platform_2_6_for_rhel 9","satellite_6_16_for_rhel 9","satellite_6_17_for_rhel 9","satellite_6_18_for_rhel 9","satellite_6_19_for_rhel 9","ai_inference_server 3.3","ai_inference_server 3.4","ansible_automation_platform 2.5","ansible_automation_platform 2.6","ansible_automation_platform 2.7","discovery 2","enterprise_linux_ai 3.3","migration_toolkit_for_applications 8.2","openshift_ai 2.25","openshift_ai 3.3","openshift_ai 3.4"],"patched":["ansible_automation_platform_2_5_for_rhel 8","satellite_6_16_for_rhel 8","ansible_automation_platform_2_5_for_rhel 9","ansible_automation_platform_2_6_for_rhel 9","satellite_6_16_for_rhel 9","satellite_6_17_for_rhel 9","satellite_6_18_for_rhel 9","satellite_6_19_for_rhel 9","ai_inference_server 3.3","ai_inference_server 3.4","ansible_automation_platform 2.5","ansible_automation_platform 2.6","ansible_automation_platform 2.7","discovery 2","enterprise_linux_ai 3.3","migration_toolkit_for_applications 8.2","openshift_ai 2.25","openshift_ai 3.3","openshift_ai 3.4"],"published":"2026-06-02","updated":"2026-09-21","sourceUpdated":"2026-09-21T20:28:31+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34993.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34993.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-34993"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2484099"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-34993"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34993"},{"url":"https://github.com/aio-libs/aiohttp/commit/dcf40f30637e8752c76781cf6703b5a236749a00"},{"url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-jg22-mg44-37j8"},{"url":"https://access.redhat.com/errata/RHSA-2026:59135"},{"url":"https://access.redhat.com/errata/RHSA-2026:50319"},{"url":"https://access.redhat.com/errata/RHSA-2026:63327"},{"url":"https://access.redhat.com/errata/RHSA-2026:59136"},{"url":"https://access.redhat.com/errata/RHSA-2026:50336"},{"url":"https://access.redhat.com/errata/RHSA-2026:63387"},{"url":"https://access.redhat.com/errata/RHSA-2026:63386"},{"url":"https://access.redhat.com/errata/RHSA-2026:63385"},{"url":"https://access.redhat.com/errata/RHSA-2026:59518"},{"url":"https://access.redhat.com/errata/RHSA-2026:69466"},{"url":"https://access.redhat.com/errata/RHSA-2026:69467"},{"url":"https://access.redhat.com/errata/RHSA-2026:69469"},{"url":"https://access.redhat.com/errata/RHSA-2026:69464"},{"url":"https://access.redhat.com/errata/RHSA-2026:50357"},{"url":"https://access.redhat.com/errata/RHSA-2026:50479"},{"url":"https://access.redhat.com/errata/RHSA-2026:50340"},{"url":"https://access.redhat.com/errata/RHSA-2026:54760"},{"url":"https://access.redhat.com/errata/RHSA-2026:62336"},{"url":"https://access.redhat.com/errata/RHSA-2026:62335"},{"url":"https://access.redhat.com/errata/RHSA-2026:43038"},{"url":"https://access.redhat.com/errata/RHSA-2026:42644"},{"url":"https://access.redhat.com/errata/RHSA-2026:24977"},{"url":"https://access.redhat.com/errata/RHSA-2026:37275"},{"url":"https://access.redhat.com/errata/RHSA-2026:60520"},{"url":"https://access.redhat.com/errata/RHSA-2026:34456"},{"url":"https://github.com/aio-libs/aiohttp"}],"tags":["csaf","vex","red-hat","cve.org","osv","pip"],"epss":0.00179,"epssPercentile":0.07666,"aliases":["GHSA-jg22-mg44-37j8","PYSEC-2026-2104"],"ecosystem":"pip","ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-06-03T13:59:36.320581Z"},"scores":{"vendor":7.2,"cna":6.4,"osv":6.4},"ingestedAt":"2026-07-13T18:57:59.703Z","slug":"CVE-2026-34993","body":"## Overview\n\nA flaw was found in AIOHTTP, an asynchronous HTTP client/server framework for asyncio and Python. An attacker could exploit this vulnerability by providing untrusted input to the `CookieJar.load()` function. This could potentially lead to arbitrary code execution, allowing the attacker to run malicious code on the affected system. This issue is most likely to occur in applications that allow attacker-controlled files to be loaded.\n\n## Vendor advisories\n\n- **RHSA-2026:59135** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59135)\n- **RHSA-2026:50319** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50319)\n- **RHSA-2026:63327** · Red Hat · fixed in: Red Hat Satellite 6.16 for RHEL 8, Red Hat Satellite 6.16 for RHEL 9 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63327)\n- **RHSA-2026:59136** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59136)\n- **RHSA-2026:50336** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50336)\n- **RHSA-2026:63387** · Red Hat · fixed in: Red Hat Satellite 6.17 for RHEL 9 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63387)\n- **RHSA-2026:63386** · Red Hat · fixed in: Red Hat Satellite 6.18 for RHEL 9 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63386)\n- **RHSA-2026:63385** · Red Hat · fixed in: Red Hat Satellite 6.19 for RHEL 9 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63385)\n- **RHSA-2026:59518** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-08-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:59518)\n- **RHSA-2026:69466** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69466)\n- **RHSA-2026:69467** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69467)\n- **Red Hat VEX** · Important · affected: Exploit Intelligence, OpenShift Lightspeed, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), … · no fix planned: Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Update Infrastructure 4 for Cloud Providers, Exploit Intelligence, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34993.json)\n- **RHSA-2026:50357** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50357)\n- **RHSA-2026:50479** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50479)\n\n**aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load()** — rated Important by Red Hat. Released 2026-06-02, updated 2026-09-21.\n\nAffected:\n\n- Exploit Intelligence\n- OpenShift Lightspeed\n- Red Hat AI Inference Server\n- Red Hat Ansible Automation Platform 2\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat Satellite 6\n- Red Hat Update Infrastructure 4 for Cloud Providers\n\nFixed:\n\n- Red Hat Ansible Automation Platform 2.5 for RHEL 8\n- Red Hat Satellite 6.16 for RHEL 8\n- Red Hat Ansible Automation Platform 2.5 for RHEL 9\n- Red Hat Ansible Automation Platform 2.6 for RHEL 9\n- Red Hat Satellite 6.16 for RHEL 9\n- Red Hat Satellite 6.17 for RHEL 9\n- Red Hat Satellite 6.18 for RHEL 9\n- Red Hat Satellite 6.19 for RHEL 9\n- Red Hat AI Inference Server 3.3\n- Red Hat AI Inference Server 3.4\n- Red Hat Ansible Automation Platform 2.5\n- Red Hat Ansible Automation Platform 2.6\n- Red Hat Ansible Automation Platform 2.7\n- Red Hat Discovery 2\n- Red Hat Enterprise Linux AI 3.3\n- Red Hat Migration Toolkit for Applications 8.2\n- Red Hat OpenShift AI 2.25\n- Red Hat OpenShift AI 3.3\n- Red Hat OpenShift AI 3.4\n\nNo fix planned:\n\n- Red Hat AI Inference Server\n- Red Hat Ansible Automation Platform 2\n- Red Hat Update Infrastructure 4 for Cloud Providers\n- Exploit Intelligence\n- OpenShift Lightspeed\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat Satellite 6\n\nNot affected:\n\n- Red Hat Ansible Automation Platform 2.6 for RHEL 10\n- Red Hat Ansible Automation Platform 2.5 for RHEL 8\n- Red Hat Satellite 6.16 for RHEL 8\n- Red Hat Ansible Automation Platform 2.5 for RHEL 9\n- Red Hat Ansible Automation Platform 2.6 for RHEL 9\n- Red Hat Satellite 6.16 for RHEL 9\n- Red Hat Satellite 6.17 for RHEL 9\n- Red Hat Satellite 6.18 for RHEL 9\n- Red Hat Satellite 6.19 for RHEL 9\n- Red Hat Ansible Automation Platform 2.5\n\n## Remediation\n\nFor details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:59135\nFor details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:50319\nBefore applying this update, make sure all previously released errata\nrelevant to your system have been applied.\n\nFor detailed instructions how to apply this update, refer to:\n\nhttps://docs.redhat.com/en/documentation/red_hat_satellite/6.16/html/updating_red_hat_satellite/index https://access.redhat.com/errata/RHSA-2026:63327\n\nWorkarounds / mitigations:\n\n- Applications using AIOHTTP that are configured to load untrusted files via the `CookieJar.load()` function should implement input sanitization prior to loading. This prevents the injection of malicious code.\n\n## Package advisory (CVE-2026-34993)\n\nAffected packages:\n\n- `aiohttp < 3.14.0`\n\nPatched in:\n\n- `aiohttp 3.14.0`\n\nSource: https://osv.dev/vulnerability/GHSA-jg22-mg44-37j8","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":39.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":208558,"id":"CVE-2026-34993","ts":1790009086539,"field":"cvss","old":"6.4","new":"7.2"},{"seq":208557,"id":"CVE-2026-34993","ts":1790009086539,"field":"severity","old":"medium","new":"high"},{"seq":83261,"id":"CVE-2026-34993","ts":1789130377896,"field":"cvss","old":"7.2","new":"6.4"},{"seq":83260,"id":"CVE-2026-34993","ts":1789130377896,"field":"severity","old":"high","new":"medium"},{"seq":82386,"id":"CVE-2026-34993","ts":1789130151757,"field":"cvss","old":"6.4","new":"7.2"},{"seq":82385,"id":"CVE-2026-34993","ts":1789130151757,"field":"severity","old":"medium","new":"high"},{"seq":81327,"id":"CVE-2026-34993","ts":1789128313203,"field":"cvss","old":"7.2","new":"6.4"},{"seq":81326,"id":"CVE-2026-34993","ts":1789128313203,"field":"severity","old":"high","new":"medium"},{"seq":80276,"id":"CVE-2026-34993","ts":1789126408794,"field":"cvss","old":"6.4","new":"7.2"},{"seq":80275,"id":"CVE-2026-34993","ts":1789126408794,"field":"severity","old":"medium","new":"high"},{"seq":77192,"id":"CVE-2026-34993","ts":1789119556880,"field":"cvss","old":"7.2","new":"6.4"},{"seq":77191,"id":"CVE-2026-34993","ts":1789119556880,"field":"severity","old":"high","new":"medium"},{"seq":76172,"id":"CVE-2026-34993","ts":1789118636862,"field":"cvss","old":"6.4","new":"7.2"},{"seq":76171,"id":"CVE-2026-34993","ts":1789118636862,"field":"severity","old":"medium","new":"high"},{"seq":75128,"id":"CVE-2026-34993","ts":1789115070591,"field":"cvss","old":"7.2","new":"6.4"},{"seq":75127,"id":"CVE-2026-34993","ts":1789115070591,"field":"severity","old":"high","new":"medium"},{"seq":74072,"id":"CVE-2026-34993","ts":1789111361883,"field":"cvss","old":"6.4","new":"7.2"},{"seq":74071,"id":"CVE-2026-34993","ts":1789111361883,"field":"severity","old":"medium","new":"high"},{"seq":73020,"id":"CVE-2026-34993","ts":1789110281699,"field":"cvss","old":"7.2","new":"6.4"},{"seq":73019,"id":"CVE-2026-34993","ts":1789110281699,"field":"severity","old":"high","new":"medium"},{"seq":71962,"id":"CVE-2026-34993","ts":1789107434991,"field":"cvss","old":"6.4","new":"7.2"},{"seq":71961,"id":"CVE-2026-34993","ts":1789107434991,"field":"severity","old":"medium","new":"high"},{"seq":70904,"id":"CVE-2026-34993","ts":1789105841343,"field":"cvss","old":"7.2","new":"6.4"},{"seq":70903,"id":"CVE-2026-34993","ts":1789105841343,"field":"severity","old":"high","new":"medium"},{"seq":69846,"id":"CVE-2026-34993","ts":1789103578387,"field":"cvss","old":"6.4","new":"7.2"},{"seq":69845,"id":"CVE-2026-34993","ts":1789103578387,"field":"severity","old":"medium","new":"high"},{"seq":68788,"id":"CVE-2026-34993","ts":1789101513438,"field":"cvss","old":"7.2","new":"6.4"},{"seq":68787,"id":"CVE-2026-34993","ts":1789101513438,"field":"severity","old":"high","new":"medium"},{"seq":67729,"id":"CVE-2026-34993","ts":1789099714467,"field":"cvss","old":"6.4","new":"7.2"},{"seq":67728,"id":"CVE-2026-34993","ts":1789099714467,"field":"severity","old":"medium","new":"high"}]}