CVE-2026-50269Aiohttp · Aiohttp
Vulnerability data via NVD (ingested)
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled input included into multipart/payload headers can be used to modify a request to inject additional headers or similar. In the unlikely situation that an application is passing user-controlled strings into MultipartWriter.append(headers=...) or Payload.headers, then an attacker may be able to modify the request to inject headers or change the contents of the request. This vulnerability is fixed in 3.14.0.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-50269product:"Aiohttp Aiohttp"http.html:"Aiohttp"More intel sources (5)
vuln:CVE-2026-50269vulnerabilities.cve_id: CVE-2026-50269CVE-2026-50269CVE-2026-50269"CVE-2026-50269" exploit -site:nvd.nist.gov