VulnSea

aiohttp vulnerabilities

CVEs whose affected-version data names the aiohttp package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

41 CVEsRSS

CVE-2024-42367Medium· 4.8
2y ago

In aiohttp, compressed files as symlinks are not protected from path traversal

In aiohttp, compressed files as symlinks are not protected from path traversal

Sunlitaiohttp · aiohttpEPSS 0.65%via OSV
CVE-2024-30251High· 7.5
2y ago

aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests

aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests

Twilightaiohttp · aiohttpEPSS 1.1%via OSV
CVE-2024-27306Medium· 6.1
2y ago

aiohttp Cross-site Scripting vulnerability on index pages for static file handling

aiohttp Cross-site Scripting vulnerability on index pages for static file handling

Sunlitaiohttp · aiohttpEPSS 0.67%via OSV
CVE-2024-23829Medium· 6.5
2y ago

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must trigger error handling to robustly match…

Sunlitaiohttp · aiohttpEPSS 1.0%via NVD
CVE-2024-23334Medium· 5.9PoC
2y ago

aiohttp is vulnerable to directory traversal

aiohttp is vulnerable to directory traversal

Twilightaiohttp · aiohttpEPSS 77%via OSV
CVE-2023-49081High· 7.2
2y ago

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for an attacker to modify the HTTP request (e.g. to insert a new header) or create a new HTTP request if the attacker co…

Twilightaiohttp · aiohttpEPSS 0.88%via NVD
CVE-2023-49082Medium· 5.3
2y ago

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even create a new HTTP request if the attacker…

Sunlitaiohttp · aiohttpEPSS 0.95%via NVD
GHSA-pjjw-qhg8-p2p9Medium
2y ago

aiohttp has vulnerable dependency that is vulnerable to request smuggling

aiohttp has vulnerable dependency that is vulnerable to request smuggling

Sunlitaiohttp · aiohttpvia OSV
CVE-2023-47627Medium· 5.3
2y ago

AIOHTTP has problems in HTTP parser (the python one, not llhttp)

AIOHTTP has problems in HTTP parser (the python one, not llhttp)

Sunlitaiohttp · aiohttpEPSS 0.86%via OSV
CVE-2023-37276Medium· 5.3PoC
3y ago

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. aiohttp v3.8.4 and earlier are bundled with llhttp v6.0.6. Vulnerable code is used by aiohttp for its HTTP request parser when available which is the default…

Twilightaiohttp · aiohttpEPSS 1.3%via NVD
CVE-2021-21330Low· 3.1
5y ago

`aiohttp` Open Redirect vulnerability (`normalize_path_middleware` middleware)

`aiohttp` Open Redirect vulnerability (`normalize_path_middleware` middleware)

Sunlitaiohttp · aiohttpEPSS 1.9%via OSV
aiohttp vulnerabilities (CVEs) — page 2 · VulnSea