VDB
EN
LOW

GHSA-mwh4-6h8g-pg8w

AIOHTTP has HTTP response splitting via \r in reason phrase

상세

### Summary

An attacker who controls the `reason` parameter when creating a `Response` may be able to inject extra headers or similar exploits.

### Impact

In the unlikely situation that an application allows untrusted data to be used in the response's `reason` parameter, then an attacker could manipulate the response to send something different from what the developer intended.

-----

Patch: https://github.com/aio-libs/aiohttp/commit/53b35a2f8869c37a133e60bf1a82a1c01642ba2b

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

PyPI / aiohttp
최초 영향 버전: 0 수정 버전: 3.13.4
수정 pip install --upgrade 'aiohttp>=3.13.4'

참고