---
id: CVE-2026-34525
aliases:
  - GHSA-c427-h43c-vf67
  - PYSEC-2026-2103
title: AIOHTTP accepts duplicate Host headers
summary: AIOHTTP accepts duplicate Host headers
severity: medium
vendor: aiohttp
product: aiohttp
ecosystem: pip
affected:
  - aiohttp < 3.13.4
patched:
  - aiohttp 3.13.4
published: '2026-04-01'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:51:01.505705751Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-c427-h43c-vf67'
references:
  - url: >-
      https://github.com/aio-libs/aiohttp/security/advisories/GHSA-c427-h43c-vf67
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-34525'
  - url: >-
      https://github.com/aio-libs/aiohttp/commit/53e2e6fc58b89c6185be7820bd2c9f40216b3000
  - url: >-
      https://github.com/aio-libs/aiohttp/commit/e00ca3cca92c465c7913c4beb763a72da9ed8349
  - url: 'https://github.com/aio-libs/aiohttp'
  - url: 'https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4'
tags:
  - osv
  - pip
epss: 0.00393
epssPercentile: 0.30595
ingestedAt: '2026-07-13T18:57:56.245Z'
---

## Overview

### Summary

Multiple Host headers were allowed in aiohttp.

### Impact

Mostly this doesn't affect aiohttp security itself, but if a reverse proxy is applying security rules depending on the target Host, it is theoretically possible that the proxy and aiohttp could process different host names, possibly resulting in bypassing a security check on the proxy and getting a request processed by aiohttp in a privileged sub app when using `Application.add_domain()`.

-----

Patch: https://github.com/aio-libs/aiohttp/commit/e00ca3cca92c465c7913c4beb763a72da9ed8349
Patch: https://github.com/aio-libs/aiohttp/commit/53e2e6fc58b89c6185be7820bd2c9f40216b3000

## Affected packages

- `aiohttp < 3.13.4`

## Remediation

Upgrade to a patched release:

- `aiohttp 3.13.4`
