CVE-2026-34520

CRITICAL

AIOHTTP: C parser (llhttp) accepts null bytes and control characters in response header values - header injection / security bypass

Title source: cna

Description

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in response headers. This issue has been patched in version 3.13.4.

Scores

CVSS v3 9.1
EPSS 0.0006
EPSS Percentile 17.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-113
Status published
Products (3)
aiohttp/aiohttp < 3.13.4
aio-libs/aiohttp < 3.13.4
pypi/aiohttp 0 - 3.13.4PyPI
Published Apr 01, 2026
Tracked Since Apr 02, 2026