{"id":"CVE-2026-50269","aliases":["GHSA-m6qw-4cw2-hm4m","PYSEC-2026-2106"],"url":"https://o3.security/vulnerability/CVE-2026-50269","summary":"AIOHTTP: CRLF injection in multipart headers","details":"AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled input included into multipart/payload headers can be used to modify a request to inject additional headers or similar. In the unlikely situation that an application is passing user-controlled strings into MultipartWriter.append(headers=...) or Payload.headers, then an attacker may be able to modify the request to inject headers or change the contents of the request. This vulnerability is fixed in 3.14.0.","published":"2026-06-22T16:30:55.789Z","modified":"2026-08-07T11:51:14.489565501Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"aiohttp","fixedVersion":"3.14.0"}],"fix":{"url":"https://github.com/aio-libs/aiohttp/commit/bf88077ebb14f4c29924b8e8904cba20c55c28b8","label":"aio-libs/aiohttp@bf88077"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50269.json"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-m6qw-4cw2-hm4m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50269"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/bf88077ebb14f4c29924b8e8904cba20c55c28b8"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:51:14.489565501Z"}}