---
schema_version: '1.0'
id: security-20260711-e9b025
url: https://osv.dev/vulnerability/GHSA-p998-jp59-783m
url_hash: e9b025536ec4c4cb650a2988f1554995bc1b64ead222b487ce8ce2c5023acd0d
canonical_url: https://osv.dev/vulnerability/GHSA-p998-jp59-783m
source: osv:ghsa
category: security/library
category_raw: cve/library
region: null
tags:
- cve
- CVE-2026-34515
- GHSA-p998-jp59-783m
- severity:CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U
- aiohttp
- PyPI
lang: en
published_at: '2026-04-01T21:26:36Z'
fetched_at: '2026-07-11T06:37:17Z'
updated_at: '2026-07-11T06:38:28Z'
status: published
content_hash: d2610431ab513ff38d509b36762cf539b5082f5250795353f5240d449031e062
license_note: full
summary: AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static
  resource handler on Windows
summary_source: rss
summary_en: AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in
  static resource handler on Windows
entities:
- name: affected
  type: UNKNOWN
- name: Uncanny Valley
  type: content
key_facts: []
related: []
related_auto:
- name: Palestinians
  type: person
  weight: 1.0
title: 'CVE-2026-34515: AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local
  File Read in static resource handler on Windows'
---

# CVE-2026-34515: AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows

## TL;DR
AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows

## Key Points
- cve / CVE-2026-34515 / GHSA-p998-jp59-783m / severity:CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U / aiohttp / PyPI

## Details
**Severity:** CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U
**Advisory:** GHSA-p998-jp59-783m (CVE-2026-34515)

**Affected (your watchlist):**
- `PyPI:aiohttp` 3.13.3 → fixed in 3.13.4 [docker/docker-strands]

**Details:**
### Summary

On Windows the static resource handler may expose information about a NTLMv2 remote path.

### Impact

If an application is running on Windows, and using aiohttp's static resource handler (not recommended in production), then it may be possible for an attacker to extract the hash from an NTLMv2 path and then extract the user's credentials from there.

-----

Patch: https://github.com/aio-libs/aiohttp/commit/0ae2aa076c84573df83fc1fdc39eec0f5862fe3d

**References:**
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-p998-jp59-783m
- https://nvd.nist.gov/vuln/detail/CVE-2026-34515
- https://github.com/aio-libs/aiohttp/commit/0ae2aa076c84573df83fc1fdc39eec0f5862fe3d
- https://github.com/aio-libs/aiohttp
- https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4

_Data: OSV.dev (upstream: ghsa) — https://osv.dev/vulnerability/GHSA-p998-jp59-783m_

## Source
元記事: [CVE-2026-34515: AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows](https://osv.dev/vulnerability/GHSA-p998-jp59-783m) — published 2026-04-01T21:26:36Z
