THREAT OPS › Threat News › [NVD] CVE-2026-54276 (MEDIUM 6.1) — AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This likely requires an open redirect vulnerability or similar on the target domain f
[NVD] CVE-2026-54276 (MEDIUM 6.1) — AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This likely requires an open redirect vulnerability or similar on the target domain f
CVE-2026-54276 CVSS: 6.1 MEDIUM Published: 2026-06-22T18:16:46.133
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This likely requires an open redirect vulnerability or similar on the target domain for an attacker to be able to execute. Further, the a
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-54276cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-54276