CVE-2026-34993

AIOHTTP Vulnerable to Deserialization of Untrusted Data

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be doing so with the user's own data, so this is unlikely to affect many applications. Version 3.14.0 patches the issue. If an application does allow attacker controlled files to be loaded, a workaround on older releases would be to sanitize the files before loading.


We have discovered 181 live websites that are affected by CVE-2026-34993.

Run a Free Instant Scan




Affected Software

Product  AIOHTTP
Category Miscellaneous
Vulnerable Domains181 live websites (100% of AIOHTTP install base)
Vulnerable Versions
  • from 0 through 3.14
Vulnerable Versions Count14 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-502 Deserialization of Untrusted Data



Details

  • Published - Jun 2, 2026
  • Updated - Jun 3, 2026

Website Distribution by Country

Number of websites using CVE-2026-34993
United States73 websites



Germany57 websites
Finland9 websites
GB5 websites
Russia5 websites
Singapore5 websites
France4 websites
China3 websites
Czech Republic2 websites

Website Distribution by TLD

Number of websites using CVE-2026-34993
.com78 websites
.fi15 websites
.net14 websites
.de9 websites
.org8 websites
.ca6 websites
.io6 websites
.ru5 websites
.info3 websites
.eu3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-34993

Top websites that are affected by CVE-2026-34993. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.org United States**,***
*********.com Germany**,***
******************.de Germany***,***
*****.************.org United States***,***
*******************.com Germany***,***
******************.at Austria***,***
********.net United States***,***
***********.ca United States***,***
*******.fi United States*,***,***
******.net China*,***,***
See full domain list

FAQ

CVE-2026-34993 is Deserialization of Untrusted Data in AIOHTTP
A total of 181 websites have been identified as vulnerable to CVE-2026-34993, based on global website indexing conducted by WebTechSurvey.
The AIOHTTP is affected by the CVE-2026-34993 vulnerability.
AIOHTTP versions up to 3.14 are vulnerable to CVE-2026-34993.
CVE-2026-34993 is resolved in version 3.14 of AIOHTTP.