AIOHTTP <3.14: CookieJar.load() RCE via untrusted input
CVE-2026-34993 Published on June 2, 2026
AIOHTTP Vulnerable to Deserialization of Untrusted Data
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be doing so with the user's own data, so this is unlikely to affect many applications. Version 3.14.0 patches the issue. If an application does allow attacker controlled files to be loaded, a workaround on older releases would be to sanitize the files before loading.
Vulnerability Analysis
CVE-2026-34993 can be exploited with local system access, requires user interaction and user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
What is a Marshaling, Unmarshaling Vulnerability?
The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVE-2026-34993 has been classified to as a Marshaling, Unmarshaling vulnerability or weakness.
Products Associated with CVE-2026-34993
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.
Affected Versions
aio-libs aiohttp:- Version < 3.14.0 is affected.
- Version 0:3.14.1-2.el8ap and below * is unaffected.
- Version 0:4.6.32-1.el8ap and below * is unaffected.
- Version 0:3.14.1-2.el9ap and below * is unaffected.
- Version 0:4.6.32-1.el9ap and below * is unaffected.
- Version 0:3.14.1-2.el9ap and below * is unaffected.
- Version 0:4.7.16-1.el9ap and below * is unaffected.
- Version 0:3.14.3-1.el8pc and below * is unaffected.
- Version 0:3.14.3-1.el9pc and below * is unaffected.
- Version 1:2.16.19-1.el9sat and below * is unaffected.
- Version 0:3.14.3-1.el9pc and below * is unaffected.
- Version 0:1.3.1-5.el9pc and below * is unaffected.
- Version 0:3.14.3-1.el9pc and below * is unaffected.
- Version 0:3.73.30-3.el9pc and below * is unaffected.
- Version 0:3.14.3-1.el9pc and below * is unaffected.
- Version 1787601159 and below * is unaffected.
- Version 1785429657 and below * is unaffected.
- Version 1785753568 and below * is unaffected.
- Version 1785646188 and below * is unaffected.
- Version 1785775360 and below * is unaffected.
- Version 1785376164 and below * is unaffected.
- Version 1785426734 and below * is unaffected.
- Version 1786638573 and below * is unaffected.
- Version 1788290314 and below * is unaffected.
- Version 1788273908 and below * is unaffected.
- Version 1788273909 and below * is unaffected.
- Version 1788260684 and below * is unaffected.
- Version 1788273977 and below * is unaffected.
- Version 1784109883 and below * is unaffected.
- Version 1780078807 and below * is unaffected.
- Version 1780078840 and below * is unaffected.
- Version 1780069179 and below * is unaffected.
- Version 1780069181 and below * is unaffected.
- Version 1783082430 and below * is unaffected.
- Version 1783024305 and below * is unaffected.
- Version 1783701598 and below * is unaffected.
- Version 1783091175 and below * is unaffected.
- Version 1782887848 and below * is unaffected.
- Version 1782472374 and below * is unaffected.
- Version 1782726504 and below * is unaffected.
- Version 1782132167 and below * is unaffected.
- Version 1782132207 and below * is unaffected.
- Version 1782132237 and below * is unaffected.
- Version 1782132240 and below * is unaffected.
- Version 1782132286 and below * is unaffected.
- Version 1782132236 and below * is unaffected.
- Version 1782132163 and below * is unaffected.
- Version 1782132297 and below * is unaffected.
- Version 1782133907 and below * is unaffected.
- Version 1786635926 and below * is unaffected.
- Version 1787169432 and below * is unaffected.
- Version 1787073866 and below * is unaffected.
- Version 1787073936 and below * is unaffected.
- Version 1787073873 and below * is unaffected.
- Version 1787073459 and below * is unaffected.
- Version 1787073611 and below * is unaffected.
- Version 1787073451 and below * is unaffected.
- Version 1787073451 and below * is unaffected.
- Version 1786622543 and below * is unaffected.
- Version 1787076778 and below * is unaffected.
- Version 1787077779 and below * is unaffected.
- Version 1787076481 and below * is unaffected.
- Version 1787074331 and below * is unaffected.
- Version 1787073913 and below * is unaffected.
- Version 1787074078 and below * is unaffected.
- Version 1787073929 and below * is unaffected.
- Version 1787073605 and below * is unaffected.
- Version 1787073546 and below * is unaffected.
- Version 1787073717 and below * is unaffected.
- Version 1787073713 and below * is unaffected.
- Version 1787073593 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.