2.7

CVSS4.0

CVE-2026-34518 - AIOHTTP: Cookie and Proxy-Authorization headers leaked on cross-origin redirect

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, when following redirects to a different origin, aiohttp drops the Authorization header, but retains the Cookie and Proxy-Authorization headers. This issue has been patched in version 3.13.4.

πŸ“… Published: April 1, 2026, 8:15 p.m. πŸ”„ Last Modified: April 17, 2026, 10 a.m.

2.7

CVSS4.0

CVE-2026-34517 - AIOHTTP: Late size enforcement for non-file multipart fields causes memory DoS

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, for some multipart form fields, aiohttp read the entire field into memory before checking client_max_size. This issue has been patched in version 3.13.4.

πŸ“… Published: April 1, 2026, 8:14 p.m. πŸ”„ Last Modified: April 15, 2026, 1:54 p.m.

6.6

CVSS4.0

CVE-2026-34516 - AIOHTTP: Multipart Header Size Bypass

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, a response with an excessive number of multipart headers may be allowed to use more memory than intended, potentially allowing a DoS vulnerability. This issue has been patched in version 3.13.4.

πŸ“… Published: April 1, 2026, 8:13 p.m. πŸ”„ Last Modified: April 15, 2026, 1:57 p.m.

6.6

CVSS4.0

CVE-2026-34515 - AIOHTTP: UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the static resource handler may expose information about a NTLMv2 remote path. This issue has been patched in version 3.13.4.

πŸ“… Published: April 1, 2026, 8:10 p.m. πŸ”„ Last Modified: April 15, 2026, 2:08 p.m.

2.7

CVSS4.0

CVE-2026-34514 - AIOHTTP: CRLF injection in multipart part content type header construction

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the content_type parameter in aiohttp could use this to inject extra headers or similar exploits. This issue has been patched in version 3.13.4.

πŸ“… Published: April 1, 2026, 8:09 p.m. πŸ”„ Last Modified: April 15, 2026, 2:13 p.m.

6.9

CVSS4.0

CVE-2026-22815 - AIOHTTP: Uncapped memory usage possible through aiohttp allowing unlimited trailer headers

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This issue has been patched in version 3.13.4.

πŸ“… Published: April 1, 2026, 8:08 p.m. πŸ”„ Last Modified: April 7, 2026, 8:07 a.m.

2.7

CVSS4.0

CVE-2026-34513 - AIOHTTP: Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation. This issue has been patched in version 3.13.4.

πŸ“… Published: April 1, 2026, 8:06 p.m. πŸ”„ Last Modified: April 15, 2026, 2:16 p.m.

9.1

CVSS3.1

CVE-2026-34456 - Reviactyl: OAuth account takeover via auto-linking

Reviactyl is an open-source game server management panel built using Laravel, React, FilamentPHP, Vite, and Go. From version 26.2.0-beta.1 to before version 26.2.0-beta.5, a vulnerability in the OAuth authentication flow allowed automatic linking of social accounts based solely on matching email ad…

πŸ“… Published: April 1, 2026, 8 p.m. πŸ”„ Last Modified: April 15, 2026, 10:45 p.m.

8.7

CVSS4.0

CVE-2026-34455 - Hi.Events: SQL Injection via Unvalidated sort_by Query Parameter in Multiple Repository Classes

Hi.Events is an open-source event management and ticket selling platform. From version 0.8.0-beta.1 to before version 1.7.1-beta, multiple repository classes pass the user-supplied sort_by query parameter directly to Eloquent's orderBy() without validation, enabling SQL injection. The application u…

πŸ“… Published: April 1, 2026, 7:56 p.m. πŸ”„ Last Modified: April 15, 2026, 2:33 p.m.

6.5

CVSS3.1

CVE-2026-34750 - Payload has Insufficient Filename Validation in Client-Upload Signed-URL Endpoints

Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/storage-azure, @payloadcms/storage-gcs, @payloadcms/storage-r2, and @payloadcms/storage-s3, the client-upload signed-URL endpoints for S3, GCS, Azure, and R2 did not properly sanitize filena…

πŸ“… Published: April 1, 2026, 7:51 p.m. πŸ”„ Last Modified: April 14, 2026, 4:42 p.m.
Total resulsts: 349182
Page 748 of 34,919
Β« previous page Β» next page
Filters