CVE-2026-34518: AIOHTTP: Cookie and Proxy-Authorization headers leaked on cross-origin redirect
Published Apr 1, 2026
·Updated
### Summary When following redirects to a different origin, aiohttp drops the Authorization header, but retains the Cookie and Proxy-Authorization headers. ### Impact The Cookie and Proxy-Authorizations headers could contain sensitive information which may be leaked to an unintended party after following a redirect. ----- Patch: https://github.com/aio-libs/aiohttp/commit/5351c980dcec7ad385730efdf4e1f4338b24fdb6
Affected Software
2 affected componentsFixes available
pip/aiohttp<=3.13.3
3.13.4
aiohttp aiohttp<3.13.4
Remediation
Event History
Apr 1, 2026
CVE Published
via MITRE·08:15 PM
Data Sourced
via MITRE·08:15 PM
DescriptionWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
RemedyAffected Software
Advisory Published
via GitHub·09:47 PM
Data Sourced
via GitHub·09:47 PM
DescriptionWeaknessAffected Software