Review reviewHigh

CVE-2026-34993

aio-libs aiohttp, Red Hat Migration Toolkit for Applications 8.2, Red Hat OpenShift AI 2.25

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be doing so with the user's own data, so this is unlikely to affect many applications. Version 3.14.0 patches the issue. If an application does allow attacker controlled files to be loaded, a workaround on older releases would be to sanitize the files before loading.

CVSS
7.3
EPSS
0.14%
3.58% percentile
CISA KEV
Not listed
Published
2026.06.03
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.14%
Technical severityCVSS 7.3

Vulnerability overview

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be doing so with the user's own data, so this is unlikely to affect many applications. Version 3.14.0 patches the issue. If an application does allow attacker controlled files to be loaded, a workaround on older releases would be to sanitize the files before loading.

Affected product and versions

Product
aio-libs aiohttp, Red Hat Migration Toolkit for Applications 8.2, Red Hat OpenShift AI 2.25
Affected versions
>= < 3.14.0, < 3.14.0
Fixed versions
3.14.0

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that aio-libs aiohttp, Red Hat Migration Toolkit for Applications 8.2, Red Hat OpenShift AI 2.25 and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CWE
CWE-502
CVE-2026-34993 — aio-libs aiohttp, Red Hat Migration Toolkit for Applications 8.2, Red Hat OpenShift AI 2.25 | SECUFOCUS NOW