CVE-2026-34514
MediumAdvisory
Published 1 Apr 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.9
- base score, highest
- EPSS
- 0.003
- 24th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 128
- of 17,781 indexed, latest versions
- Container images
- 131
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
AIOHTTP has CRLF injection through multipart part content type header construction
Carried by container images the latest versions of 128 of 17,781 indexed charts deploy, on 131 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| aiohttppypi | 3.4.4, 3.5.4, 3.6.2, 3.7.1+30 more | 3.13.4 | 131 |
| python-aiohttpdeb | 3.8.4-1, 3.11.16-1+deb13u1 | no fix listed | 2 |
- OSV records
- DEBIAN-CVE-2026-34514GHSA-2vrm-gr82-f7m5
- Also known as
- PYSEC-2026-2096
Charts affected
128 by stars
Container images carrying it
131 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| opea/ | 0c25aab3f106 | aiohttp | 3.13.4 | 4 |
| quay.io/ | 6545dac92173 | aiohttp | 3.13.4 | 3 |
| matrixdotorg/ | ba6a587fa508 | aiohttp | 3.13.4 | 2 |
| opea/ | 5c9639de61c1 | aiohttp | 3.13.4 | 2 |
| opea/ | e48613afb191 | aiohttp | 3.13.4 | 2 |
| opea/ | eb746b263705 | aiohttp | 3.13.4 | 2 |
| vdiogov/ | 6945f84f0058 | aiohttp python-aiohttp | 3.13.4 no fix listed | 2 |
| ghcr.io/ | fd8d3e6e4cdf | aiohttp | 3.13.4 | 2 |
| ghcr.io/ | 647a3c938d31 | aiohttp | 3.13.4 | 2 |
| acockburn/ | 3a93281d7e94 | aiohttp | 3.13.4 | 1 |
| alerta/ | 4786b9eaa606 | aiohttp | 3.13.4 | 1 |
| apache/ | 64e58748b6b9 | aiohttp | 3.13.4 | 1 |
| apache/ | ce90bdc3d2af | aiohttp | 3.13.4 | 1 |
| apache/ | e5560ad0b86e | aiohttp | 3.13.4 | 1 |
| apache/ | 975ab033580d | aiohttp | 3.13.4 | 1 |
| apecloud/ | 8ac9947a2c84 | aiohttp | 3.13.4 | 1 |
| aristidetm/ | 469dbc951224 | aiohttp | 3.13.4 | 1 |
| aristidetm/ | ccb516cb8474 | aiohttp | 3.13.4 | 1 |
| assistiot/ | 0aacefac9677 | aiohttp | 3.13.4 | 1 |
| assistiot/ | 7d6a0d534c7f | aiohttp | 3.13.4 | 1 |
| baserow/ | e0b3c8130b91 | aiohttp | 3.13.4 | 1 |
| baserow/ | df0c42eb67e8 | aiohttp | 3.13.4 | 1 |
| berkeleyskypilot/ | 8da2f3cda472 | aiohttp | 3.13.4 | 1 |
| chiefonboarding/ | 59bc7aa60fe7 | aiohttp | 3.13.4 | 1 |
| ciuse99/ | d72768245ef5 | aiohttp | 3.13.4 | 1 |
| clowder/ | 11f3d844e4c0 | aiohttp | 3.13.4 | 1 |
| clowder/ | 14155326c7b9 | aiohttp | 3.13.4 | 1 |
| clowder/ | bf146f1ca24f | aiohttp | 3.13.4 | 1 |
| codaprotocol/ | 37c68e67a401 | aiohttp | 3.13.4 | 1 |
| cznic/ | fe71c5214fdc | aiohttp python-aiohttp | 3.13.4 no fix listed | 1 |
| datamate/ | 2dd66b722464 | aiohttp | 3.13.4 | 1 |
| deepflowce/ | a1888d35e787 | aiohttp | 3.13.4 | 1 |
| devopstales/ | 75136aa7a26e | aiohttp | 3.13.4 | 1 |
| dserio83/ | 6b3d9115fee2 | aiohttp | 3.13.4 | 1 |
| evk02/ | ef6ff257ef35 | aiohttp | 3.13.4 | 1 |
| factly/ | ca5bc71d1d5c | aiohttp | 3.13.4 | 1 |
| flag5/ | 4ad5748bfcc6 | aiohttp | 3.13.4 | 1 |
| galaxy/ | e5c265fe9fcd | aiohttp | 3.13.4 | 1 |
| galaxy/ | e50a890e24c9 | aiohttp | 3.13.4 | 1 |
| guillh/ | 4fb99dbc32b2 | aiohttp | 3.13.4 | 1 |
| halkeye/ | 77b05e95fdb5 | aiohttp | 3.13.4 | 1 |
| hayk96/ | 86377705e9e3 | aiohttp | 3.13.4 | 1 |
| hhyo/ | 1aa41843419e | aiohttp | 3.13.4 | 1 |
| hjacobs/ | 431f1bf013d0 | aiohttp | 3.13.4 | 1 |
| hjacobs/ | b44a9cf81a2f | aiohttp | 3.13.4 | 1 |
| homeassistant/ | 021e2afc6e57 | aiohttp | 3.13.4 | 1 |
| homeassistant/ | 8d000332b09b | aiohttp | 3.13.4 | 1 |
| iosifache/ | 85df3f04b5da | aiohttp | 3.13.4 | 1 |
| jupyterhub/ | 5a0ceed1300a | aiohttp | 3.13.4 | 1 |
| knspar/ | 0c4f0543ee58 | aiohttp | 3.13.4 | 1 |