Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-59881MediumAIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
CVE-2026-54276Medium· 6.1AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This likely requires an open redirect vuln…
CVE-2026-54280High· 7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar…
CVE-2026-50269Lowaiohttp: CRLF injection in multipart headers
CVE-2026-54279Lowaiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence
CVE-2026-54277Mediumaiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines
CVE-2026-54278Mediumaiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup
CVE-2026-54273Mediumaiohttp: HTTP/1 Pipelined Requests Queue Without Limit
CVE-2026-54275Lowaiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
CVE-2026-54274Mediumaiohttp: Incomplete websocket frame payloads bypass memory limits
CVE-2026-47265MediumAIOHTTP is vulnerable to cross-origin redirect with per-request cookies
CVE-2026-22815Mediumaiohttp allows unlimited trailer headers, leading to possible uncapped memory usage
CVE-2026-34515MediumAIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows
CVE-2026-34519LowAIOHTTP has HTTP response splitting via \r in reason phrase
CVE-2026-34516High· 7.5AIOHTTP has a Multipart Header Size Bypass
CVE-2026-34513LowAIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector
CVE-2026-34525MediumAIOHTTP accepts duplicate Host headers
CVE-2026-34518Medium· 5.3AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect
CVE-2026-34520Critical· 9.1AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass
CVE-2026-34517LowAIOHTTP has late size enforcement for non-file multipart fields causes memory DoS
CVE-2026-34514LowAIOHTTP has CRLF injection through multipart part content type header construction
CVE-2025-69230Medium· 5.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can lead to a logging storm. If the cookies attribute is accessed in an application, then an a…
CVE-2025-69225LowAIOHTTP has unicode match groups in regexes for ASCII protocol elements
CVE-2025-69229MediumAIOHTTP vulnerable to DoS through chunked messages
CVE-2025-69224LowAIOHTTP's unicode processing of header values could cause parsing discrepancies
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.