VulnSea

aiohttp vulnerabilities

CVEs whose affected-version data names the aiohttp package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

41 CVEsRSS

CVE-2026-59881Medium
1mo ago

AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate

AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate

Sunlitaiohttp · aiohttpEPSS 0.30%via OSV
CVE-2026-54276Medium· 6.1
3mo ago

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This likely requires an open redirect vuln…

Sunlitaiohttp · aiohttpEPSS 0.31%via NVD
CVE-2026-54280High· 7.5
3mo ago

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar…

Twilightaiohttp · aiohttpEPSS 0.28%via NVD
CVE-2026-50269Low
3mo ago

aiohttp: CRLF injection in multipart headers

aiohttp: CRLF injection in multipart headers

Sunlitaiohttp · aiohttpEPSS 0.30%via OSV
CVE-2026-54279Low
3mo ago

aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence

aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence

Sunlitaiohttp · aiohttpEPSS 0.28%via OSV
CVE-2026-54277Medium
3mo ago

aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines

aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines

Sunlitaiohttp · aiohttpEPSS 0.32%via OSV
CVE-2026-54278Medium
3mo ago

aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup

aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup

Sunlitaiohttp · aiohttpEPSS 0.40%via OSV
CVE-2026-54273Medium
3mo ago

aiohttp: HTTP/1 Pipelined Requests Queue Without Limit

aiohttp: HTTP/1 Pipelined Requests Queue Without Limit

Sunlitaiohttp · aiohttpEPSS 0.28%via OSV
CVE-2026-54275Low
3mo ago

aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections

aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections

Sunlitaiohttp · aiohttpEPSS 0.27%via OSV
CVE-2026-54274Medium
3mo ago

aiohttp: Incomplete websocket frame payloads bypass memory limits

aiohttp: Incomplete websocket frame payloads bypass memory limits

Sunlitaiohttp · aiohttpEPSS 0.30%via OSV
CVE-2026-47265Medium
3mo ago

AIOHTTP is vulnerable to cross-origin redirect with per-request cookies

AIOHTTP is vulnerable to cross-origin redirect with per-request cookies

Sunlitaiohttp · aiohttpEPSS 0.15%via OSV
CVE-2026-22815Medium
5mo ago

aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage

aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage

Sunlitaiohttp · aiohttpEPSS 0.44%via OSV
CVE-2026-34515Medium
5mo ago

AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows

AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows

Sunlitaiohttp · aiohttpEPSS 0.43%via OSV
CVE-2026-34519Low
5mo ago

AIOHTTP has HTTP response splitting via \r in reason phrase

AIOHTTP has HTTP response splitting via \r in reason phrase

Sunlitaiohttp · aiohttpEPSS 0.29%via OSV
CVE-2026-34516High· 7.5
5mo ago

AIOHTTP has a Multipart Header Size Bypass

AIOHTTP has a Multipart Header Size Bypass

Twilightaiohttp · aiohttpEPSS 0.44%via OSV
CVE-2026-34513Low
5mo ago

AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector

AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector

Sunlitaiohttp · aiohttpEPSS 0.44%via OSV
CVE-2026-34525Medium
5mo ago

AIOHTTP accepts duplicate Host headers

AIOHTTP accepts duplicate Host headers

Sunlitaiohttp · aiohttpEPSS 0.29%via OSV
CVE-2026-34518Medium· 5.3
5mo ago

AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect

AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect

Sunlitaiohttp · aiohttpEPSS 0.34%via OSV
CVE-2026-34520Critical· 9.1
5mo ago

AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass

AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass

Midnightaiohttp · aiohttpEPSS 0.46%via OSV
CVE-2026-34517Low
5mo ago

AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS

AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS

Sunlitaiohttp · aiohttpEPSS 0.38%via OSV
CVE-2026-34514Low
5mo ago

AIOHTTP has CRLF injection through multipart part content type header construction

AIOHTTP has CRLF injection through multipart part content type header construction

Sunlitaiohttp · aiohttpEPSS 0.32%via OSV
CVE-2025-69230Medium· 5.3
8mo ago

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can lead to a logging storm. If the cookies attribute is accessed in an application, then an a…

Sunlitaiohttp · aiohttpEPSS 0.37%via NVD
CVE-2025-69225Low
8mo ago

AIOHTTP has unicode match groups in regexes for ASCII protocol elements

AIOHTTP has unicode match groups in regexes for ASCII protocol elements

Sunlitaiohttp · aiohttpEPSS 0.28%via OSV
CVE-2025-69229Medium
8mo ago

AIOHTTP vulnerable to DoS through chunked messages

AIOHTTP vulnerable to DoS through chunked messages

Sunlitaiohttp · aiohttpEPSS 0.40%via OSV
CVE-2025-69224Low
8mo ago

AIOHTTP's unicode processing of header values could cause parsing discrepancies

AIOHTTP's unicode processing of header values could cause parsing discrepancies

Sunlitaiohttp · aiohttpEPSS 0.24%via OSV
CVE-2025-69226Low
8mo ago

AIOHTTP vulnerable to brute-force leak of internal static file path components

AIOHTTP vulnerable to brute-force leak of internal static file path components

Sunlitaiohttp · aiohttpEPSS 0.36%via OSV
CVE-2025-69223High· 7.5
8mo ago

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that …

Twilightaiohttp · aiohttpEPSS 0.57%via NVD
CVE-2025-53643Low
1y ago

AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections

AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections

Sunlitaiohttp · aiohttpEPSS 0.31%via OSV
CVE-2024-52304Medium
1y ago

aiohttp allows request smuggling due to incorrect parsing of chunk extensions

aiohttp allows request smuggling due to incorrect parsing of chunk extensions

Sunlitaiohttp · aiohttpEPSS 0.56%via OSV
CVE-2024-52303High· 7.5
1y ago

aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method

aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method

Twilightaiohttp · aiohttpEPSS 0.59%via OSV
aiohttp vulnerabilities (CVEs) · VulnSea