Résumé
AIOHTTP: HTTP request smuggling via WebSocket upgrade
Détails de l’avis
Summary
The HTTP parsers were vulnerable to a request smuggling attack relating to WebSocket upgrades.
Impact
If using the server-side component, it may be possible for an attacker to execute a request smuggling vulnerability using an edge case in the WebSocket upgrade procedure. AIOHTT is unaware of any public exploit code.
Patch: https://github.com/aio-libs/aiohttp/commit/6ae358f0983c3f4d6f67692b2f8e65dc8e091c98
Références
- https://github.com/advisories/GHSA-mfx4-hv73-q22v
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mfx4-hv73-q22v
- https://github.com/aio-libs/aiohttp/pull/13017
- https://github.com/aio-libs/aiohttp/commit/6ae358f0983c3f4d6f67692b2f8e65dc8e091c98
- https://github.com/aio-libs/aiohttp/releases/tag/v3.14.2
Vulnérabilités liées
Tout Supply chain →- MEDIUMCVE-2026-55087
ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header
- MEDIUMCVE-2026-62899
Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability
- MEDIUMCVE-2026-71554
h2: Duplicate Host header could facilitate request smuggling
- HIGHCVE-2026-71324
Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool
- MEDIUMCVE-2026-16728
undici vulnerable to downstream response desynchronization via retry interceptor
- HIGHGHSA-46q4-43ph-c6fr#org.http4s:blaze-http_3
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)