HIGH7.5
PYSEC-2026-2112
Quick fix
PYSEC-2026-2112 — aiohttp: upgrade to the fixed version with the command below.
pip install --upgrade 'aiohttp>=3.14.1'Details
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status. This vulnerability is fixed in 3.14.1.
Are you affected?
Enter the version of the package you're using.