VulnSea

aiohttp has 41 CVEs on record between 2021 and 2026. Disclosures have slowed: 1 in the last 90 days after 20 in the 90 before. The busiest recent month was April 2026 with 10. The median CVSS is 6.1 (medium), with 1 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-770 (4) and CWE-20 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.1
Publish → KEV
Last 90 days
1 prev 20

Products

  • aiohttp 41
41
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

aiohttp vulnerabilities

CVEs affecting aiohttp, newest first. Open any entry for full detail, references, and exploit status.

41 CVEsRSS

CVE-2024-42367Medium· 4.8
2y ago

In aiohttp, compressed files as symlinks are not protected from path traversal

In aiohttp, compressed files as symlinks are not protected from path traversal

Sunlitaiohttp · aiohttpEPSS 0.65%via OSV
CVE-2024-30251High· 7.5
2y ago

aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests

aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests

Twilightaiohttp · aiohttpEPSS 1.1%via OSV
CVE-2024-27306Medium· 6.1
2y ago

aiohttp Cross-site Scripting vulnerability on index pages for static file handling

aiohttp Cross-site Scripting vulnerability on index pages for static file handling

Sunlitaiohttp · aiohttpEPSS 0.67%via OSV
CVE-2024-23829Medium· 6.5
2y ago

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must trigger error handling to robustly match…

Sunlitaiohttp · aiohttpEPSS 1.0%via NVD
CVE-2024-23334Medium· 5.9PoC
2y ago

aiohttp is vulnerable to directory traversal

aiohttp is vulnerable to directory traversal

Twilightaiohttp · aiohttpEPSS 77%via OSV
CVE-2023-49081High· 7.2
2y ago

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for an attacker to modify the HTTP request (e.g. to insert a new header) or create a new HTTP request if the attacker co…

Twilightaiohttp · aiohttpEPSS 0.88%via NVD
CVE-2023-49082Medium· 5.3
2y ago

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even create a new HTTP request if the attacker…

Sunlitaiohttp · aiohttpEPSS 0.95%via NVD
GHSA-pjjw-qhg8-p2p9Medium
2y ago

aiohttp has vulnerable dependency that is vulnerable to request smuggling

aiohttp has vulnerable dependency that is vulnerable to request smuggling

Sunlitaiohttp · aiohttpvia OSV
CVE-2023-47627Medium· 5.3
2y ago

AIOHTTP has problems in HTTP parser (the python one, not llhttp)

AIOHTTP has problems in HTTP parser (the python one, not llhttp)

Sunlitaiohttp · aiohttpEPSS 0.86%via OSV
CVE-2023-37276Medium· 5.3PoC
3y ago

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. aiohttp v3.8.4 and earlier are bundled with llhttp v6.0.6. Vulnerable code is used by aiohttp for its HTTP request parser when available which is the default…

Twilightaiohttp · aiohttpEPSS 1.3%via NVD
CVE-2021-21330Low· 3.1
5y ago

`aiohttp` Open Redirect vulnerability (`normalize_path_middleware` middleware)

`aiohttp` Open Redirect vulnerability (`normalize_path_middleware` middleware)

Sunlitaiohttp · aiohttpEPSS 1.9%via OSV
aiohttp vulnerabilities (CVEs) — page 2 · VulnSea