CVE-2018-1000814: Aio-Libs Aiohttp Session
Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.
aio-libs aiohttp-session version 2.6.0 and earlier contains a Other/Unknown vulnerability in EncryptedCookieStorage and NaClCookieStorage that can result in Non-expiring sessions / Infinite lifespan. This attack appear to be exploitable via Recreation of a cookie post-expiry with the same value.
Affected products
- Aio-Libs Aiohttp Session: up to and including 2.6.0
Published 2018-12-20. Last modified 2026-06-17.