---
schema_version: '1.0'
id: security-20260714-1775ac
url: https://osv.dev/vulnerability/PYSEC-2026-2112
url_hash: 1775acf1ea31de8bbbc80cdcb6407fee825c6a0f53c9ec1bde3778b23827e35a
canonical_url: https://osv.dev/vulnerability/PYSEC-2026-2112
source: osv:pypa
category: security/library
category_raw: cve/library
region: null
tags:
- cve
- CVE-2026-54279
- PYSEC-2026-2112
- severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- aiohttp
- PyPI
lang: en
published_at: '2026-06-22T18:16:46Z'
fetched_at: '2026-07-14T06:42:23Z'
updated_at: '2026-07-14T06:42:55Z'
status: published
content_hash: e314b39592bf4ea66a48e57f6c1cf5c0178a8a140d8ecad38c05772a5a18d8fd
license_note: full
summary: AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python.
  Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then
  restored later with CookieJar.load() lose their host-only status. This vulnerability
  is fixed in 3.14.1.
summary_source: rss
summary_en: AIOHTTP is an asynchronous HTTP client/server framework for asyncio and
  Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save()
  and then restored later with CookieJar.load() lose their host-only status. This
  vulnerability is fixed in 3.14.1.
entities: []
key_facts: []
related: []
related_auto: []
title: CVE-2026-54279 — aiohttp
---

# CVE-2026-54279 — aiohttp

## TL;DR
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status. This vulnerability is fixed in 3.14.1.

## Key Points
- cve / CVE-2026-54279 / PYSEC-2026-2112 / severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H / aiohttp / PyPI

## Details
**Severity:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
**Advisory:** PYSEC-2026-2112 (CVE-2026-54279)

**Affected (your watchlist):**
- `PyPI:aiohttp` 3.13.3 → fixed in 3.14.1 [docker/docker-strands]

**Details:**
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status. This vulnerability is fixed in 3.14.1.

**References:**
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-2fqr-mr3j-6wp8
- https://github.com/aio-libs/aiohttp/commit/a329a7aacad5284f087af36103aff778746da0f2

_Data: OSV.dev (upstream: pypa) — https://osv.dev/vulnerability/PYSEC-2026-2112_

## Source
元記事: [CVE-2026-54279 — aiohttp](https://osv.dev/vulnerability/PYSEC-2026-2112) — published 2026-06-22T18:16:46Z
