CVE-2026-34519 | aio-libs aiohttp up to 3.13.3 Reason response splitting (GHSA-mwh4-6h8g-pg8w / CNNVD-202604-220)
A vulnerability labeled as problematic has been found in aio-libs aiohttp up to 3.13.3. This impacts an unknown function. Such manipulation of the argument Reason leads to http response splitting.
This vulnerability is referenced as CVE-2026-34519. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.