Executive brief
aiohttp is a Python library for building asynchronous web applications. A specially crafted HTTP Cookie header can trigger excessive warning-level logs in applications that access the cookies attribute, potentially degrading performance and filling log storage. This is resolved in version 3.13.3.
Technical details
The vulnerability is a denial-of-service via logging storm in aiohttp's cookie parser. When an application accesses the cookies attribute of a request and a malformed Cookie header is present, the parser generates repeated warning logs for each invalid cookie, rather than logging once per header. An attacker can craft a Cookie header with multiple invalid entries to flood the application logs. The attack requires network access to send a specially crafted HTTP request to an application using aiohttp. The fix, merged in commit 64629a0, implements per-header logging limits to prevent the storm.
Affected products
- aio-libs aiohttp <=3.13.2
Timeline
- 2026-01-06: disclosed
- 2026-01-05: patched: Fix available in version 3.13.3