Low severityGHSA Advisory· Published Jun 15, 2026· Updated Jun 15, 2026
aiohttp: CRLF injection in multipart headers
CVE-2026-50269
Description
Summary
Attacker-controlled input included into multipart/payload headers can be used to modify a request to inject additional headers or similar.
Impact
In the unlikely situation that an application is passing user-controlled strings into MultipartWriter.append(headers=...) or Payload.headers, then an attacker may be able to modify the request to inject headers or change the contents of the request.
Workaround
Sanitise such user input.
-----
Patch: https://github.com/aio-libs/aiohttp/commit/bf88077ebb14f4c29924b8e8904cba20c55c28b8
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
aiohttpPyPI | < 3.14.0 | 3.14.0 |
Affected products
12- osv-coords11 versionspkg:apk/chainguard/py3.10-vllm-cuda-12.4pkg:apk/chainguard/py3.10-vllm-cuda-12.9pkg:apk/chainguard/py3.10-vllm-cuda-13.0pkg:apk/chainguard/py3.12-vllm-cuda-12.4pkg:apk/chainguard/py3.12-vllm-cuda-12.9pkg:apk/chainguard/py3.12-vllm-cuda-13.0pkg:apk/chainguard/py3.13-scanner-test-libraries-aiohttppkg:apk/chainguard/py3.13-vllm-cuda-12.9pkg:apk/chainguard/py3.13-vllm-cuda-13.0pkg:pypi/aiohttppkg:rpm/opensuse/python-aiohttp&distro=openSUSE%20Tumbleweed
< 0.18.1-r3+ 10 more
- (no CPE)range: < 0.18.1-r3
- (no CPE)range: < 0.19.1-r0
- (no CPE)range: < 0.20.2-r1
- (no CPE)range: < 0.18.1-r3
- (no CPE)range: < 0.19.1-r0
- (no CPE)range: < 0.20.2-r1
- (no CPE)range: < 0.0.1-r3
- (no CPE)range: < 0.19.1-r0
- (no CPE)range: < 0.20.2-r1
- (no CPE)range: < 3.14.0
- (no CPE)range: < 3.14.1-1.1
Patches
Vulnerability mechanics
References
3News mentions
1- Aiohttp: Nine CVEs Disclosed in a Single Day, Five Memory-Exhaustion DoS FlawsVypr Intelligence · Jun 15, 2026