aiohttp has 41 CVEs on record between 2021 and 2026. Disclosures have slowed: 1 in the last 90 days after 20 in the 90 before. The busiest recent month was April 2026 with 10. The median CVSS is 6.1 (medium), with 1 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-770 (4) and CWE-20 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.1
- Publish → KEV
- —
- Last 90 days
- 1 prev 20
Worst active — by depth score
CVE-2024-23334Medium· 5.9aiohttp is vulnerable to directory traversal60CVE-2026-34520Critical· 9.1AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass50CVE-2026-54280High· 7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python41CVE-2026-34516High· 7.5AIOHTTP has a Multipart Header Size Bypass41CVE-2025-69223High· 7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python41
aiohttp vulnerabilities
CVEs affecting aiohttp, newest first. Open any entry for full detail, references, and exploit status.
41 CVEsRSS
CVE-2024-42367Medium· 4.8In aiohttp, compressed files as symlinks are not protected from path traversal
In aiohttp, compressed files as symlinks are not protected from path traversal
CVE-2024-30251High· 7.5aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests
aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests
CVE-2024-27306Medium· 6.1aiohttp Cross-site Scripting vulnerability on index pages for static file handling
aiohttp Cross-site Scripting vulnerability on index pages for static file handling
CVE-2024-23829Medium· 6.5aiohttp is an asynchronous HTTP client/server framework for asyncio and Python
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must trigger error handling to robustly match…
CVE-2024-23334Medium· 5.9PoCaiohttp is vulnerable to directory traversal
aiohttp is vulnerable to directory traversal
CVE-2023-49081High· 7.2aiohttp is an asynchronous HTTP client/server framework for asyncio and Python
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for an attacker to modify the HTTP request (e.g. to insert a new header) or create a new HTTP request if the attacker co…
CVE-2023-49082Medium· 5.3aiohttp is an asynchronous HTTP client/server framework for asyncio and Python
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even create a new HTTP request if the attacker…
GHSA-pjjw-qhg8-p2p9Mediumaiohttp has vulnerable dependency that is vulnerable to request smuggling
aiohttp has vulnerable dependency that is vulnerable to request smuggling
CVE-2023-47627Medium· 5.3AIOHTTP has problems in HTTP parser (the python one, not llhttp)
AIOHTTP has problems in HTTP parser (the python one, not llhttp)
CVE-2023-37276Medium· 5.3PoCaiohttp is an asynchronous HTTP client/server framework for asyncio and Python
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. aiohttp v3.8.4 and earlier are bundled with llhttp v6.0.6. Vulnerable code is used by aiohttp for its HTTP request parser when available which is the default…
CVE-2021-21330Low· 3.1`aiohttp` Open Redirect vulnerability (`normalize_path_middleware` middleware)
`aiohttp` Open Redirect vulnerability (`normalize_path_middleware` middleware)