---
schema_version: '1.0'
id: security-20260711-546e87
url: https://osv.dev/vulnerability/GHSA-2fqr-mr3j-6wp8
url_hash: 546e87161a3a15aba29bef7f01db06526cdec03d1540a5010582723193b40c4f
canonical_url: https://osv.dev/vulnerability/GHSA-2fqr-mr3j-6wp8
source: osv:ghsa
category: security/library
category_raw: cve/library
region: null
tags:
- cve
- CVE-2026-54279
- GHSA-2fqr-mr3j-6wp8
- severity:CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:U
- aiohttp
- PyPI
lang: en
published_at: '2026-06-15T20:08:51Z'
fetched_at: '2026-07-11T06:37:17Z'
updated_at: '2026-07-11T06:37:45Z'
status: published
content_hash: e7866524cdb88d024dbe368b2d74290153256778924b6084ac5567f69209cf50
license_note: full
summary: 'aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence'
summary_source: rss
summary_en: 'aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence'
entities:
- name: Aid worker Mohammed al-Wahidi had become a prominent humanitarian figure during
    the Israel-Hamas war...
  type: content
- name: τ²-bench airline domain
  type: location
key_facts: []
related: []
related_auto: []
title: 'CVE-2026-54279: aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar
  Persistence'
---

# CVE-2026-54279: aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence

## TL;DR
aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence

## Key Points
- cve / CVE-2026-54279 / GHSA-2fqr-mr3j-6wp8 / severity:CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:U / aiohttp / PyPI

## Details
**Severity:** CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:U
**Advisory:** GHSA-2fqr-mr3j-6wp8 (CVE-2026-54279)

**Affected (your watchlist):**
- `PyPI:aiohttp` 3.13.3 → fixed in 3.14.1 [docker/docker-strands]

**Details:**
### Summary

Host-only cookies that are saved with ``CookieJar.save()`` and then restored later with ``CookieJar.load()`` lose their host-only status.

### Impact

Host-only cookies that have been loaded from disk may get sent to subdomains that previously should have been disallowed.

-----

Patch: https://github.com/aio-libs/aiohttp/commit/a329a7aacad5284f087af36103aff778746da0f2

**References:**
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-2fqr-mr3j-6wp8
- https://github.com/aio-libs/aiohttp

_Data: OSV.dev (upstream: ghsa) — https://osv.dev/vulnerability/GHSA-2fqr-mr3j-6wp8_

## Source
元記事: [CVE-2026-54279: aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence](https://osv.dev/vulnerability/GHSA-2fqr-mr3j-6wp8) — published 2026-06-15T20:08:51Z
