aiohttp-session Session Fixation vulnerability
High severity
GitHub Reviewed
Published
Sep 13, 2018
to the GitHub Advisory Database
•
Updated Jul 11, 2025
Description
Published by the National Vulnerability Database
Jun 26, 2018
Published to the GitHub Advisory Database
Sep 13, 2018
Reviewed
Jun 16, 2020
Last updated
Jul 11, 2025
The pypi package aiohttp-session before 2.4.0 contained a Session Fixation vulnerability in
load_session
function for RedisStorage that can result in Session Hijacking. This attack appear to be exploitable via Any method that allows setting session cookies (?session=<>
, or meta tags or script tags with Set-Cookie).References