OSV 1.4.0 · github-reviewed · 修改于 2026-06-16 04:07
发布时间
2026-06-16 04:07
GitHub 审查时间
2026-06-16 04:07
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/06/GHSA-m6qw-4cw2-hm4m/GHSA-m6qw-4cw2-hm4m.json
Attacker-controlled input included into multipart/payload headers can be used to modify a request to inject additional headers or similar.
In the unlikely situation that an application is passing user-controlled strings into MultipartWriter.append(headers=...) or Payload.headers, then an attacker may be able to modify the request to inject headers or change the contents of the request.
Sanitise such user input.
Patch: https://github.com/aio-libs/aiohttp/commit/bf88077ebb14f4c29924b8e8904cba20c55c28b8