Skip to content

Cookie from subdomain can remove Host-Only Scope from existing cookies

Low
Dreamsorcerer published GHSA-gx76-c99x-2c96 Oct 7, 2026

Package

pip aiohttp (pip)

Affected versions

<=3.14.3

Patched versions

3.14.4

Description

Summary

A subdomain can remove the Host-Only flag from an existing cookie to a parent domain.

Impact

A user accessing untrusted subdomains could see their Host-Only protections stripped from cookies. Given most usecases won't reflect these cookies to a browser, the impact is limited.


Patch: 6a07c17

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs

Credits