CVE-2026-34514: AIOHTTP: CRLF injection in multipart part content type header construction
Published Apr 1, 2026
·Updated
### Summary An attacker who controls the `content_type` parameter in aiohttp could use this to inject extra headers or similar exploits. ### Impact If an application allows untrusted data to be used for the multipart `content_type` parameter when constructing a request, an attacker may be able to manipulate the request to send something other than what the developer intended. ----- Patch: https://github.com/aio-libs/aiohttp/commit/9a6ada97e2c6cf1ce31727c6c9fcea17c21f6f06
Affected Software
2 affected componentsFixes available
pip/aiohttp<=3.13.3
3.13.4
aiohttp aiohttp<3.13.4
Remediation
Event History
Apr 1, 2026
CVE Published
via MITRE·08:09 PM
Data Sourced
via MITRE·08:09 PM
DescriptionWeakness
Data Sourced
via NVD·09:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·09:20 PM
Data Sourced
via GitHub·09:20 PM
DescriptionWeaknessAffected Software