Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.3 PyPI

AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect

GHSA-966j-vmvw-g2g9 · CVE-2026-34518

Published · Modified

Description

Summary

When following redirects to a different origin, aiohttp drops the Authorization header, but retains the Cookie and Proxy-Authorization headers.

Impact

The Cookie and Proxy-Authorizations headers could contain sensitive information which may be leaked to an unintended party after following a redirect.


Patch: https://github.com/aio-libs/aiohttp/commit/5351c980dcec7ad385730efdf4e1f4338b24fdb6

Ready to move

Start Securing

Free, no credit card | First findings in minutes