GHSA-2fqr-mr3j-6wp8 on CTRL-OS 26.05
Aliases: GHSA-2fqr-mr3j-6wp8, CVE-2026-54279
Packages: python3Packages.aiohttp
Status: Plausible
Advisory Information
Summary
Host-only cookies that are saved with
CookieJar.save()and then restored later withCookieJar.load()lose their host-only status.Impact
Host-only cookies that have been loaded from disk may get sent to subdomains that previously should have been disallowed.
Patch: https://github.com/aio-libs/aiohttp/commit/a329a7aacad5284f087af36103aff778746da0f2
Updates
2026-07-10 22:13 CEST
Metadata changes:
- Status for package
python3Packages.aiohttp: “Plausible”
(Amended on: 2026-07-10 22:14 CEST)
2026-07-10 20:35 CEST
Metadata changes:
- Status for package
python3Packages.aiohttp: “New”