Executive brief
AIOHTTP is a popular Python library used by developers to build web servers and clients. A security flaw in its authentication component could allow an attacker to trick the library into sending sensitive login information to a malicious website. This typically occurs if the application follows a link that redirects to an attacker-controlled server, potentially leading to the theft of user credentials.
Technical details
A vulnerability exists in AIOHTTP's DigestAuthMiddleware where authentication credentials are not strictly scoped to the original request's origin. When the client follows a cross-origin redirect, the middleware may respond to a digest authentication challenge from the new, potentially malicious origin using the original credentials. An attacker could exploit this by leveraging an open redirect on a trusted site to capture the user's authentication digest. While the attacker only receives the digest rather than the plaintext password, they may be able to crack it if weak cryptography is used or if the user reuses passwords. The issue is fixed in version 3.14.1 by scoping credentials to the initial request origin.
Affected products
- aio-libs aiohttp < 3.14.1
Timeline
- 2026-06-07: patched: Fix committed to repository
- 2026-06-08: advisory: GitHub Security Advisory published
- 2026-06-22: disclosed: NVD publication date