aiohttp records
44 published records for vendor aiohttp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 97.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')8
- CWE-770 Allocation of Resources Without Limits or Throttling8
- CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')3
- CWE-20 Improper Input Validation3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
The weakness classes this vendor ships most often: where to look.
CWEAll records
44 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
53Plan | CVE-2024-23334Proof of concept | aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversalaiohttp · aiohttp · CWE-22 | High7.5 | — | 76.9% | Jan 29, 2024 |
34Monitor | CVE-2024-52303No exploit | aiohttp memory leak when middleware is enabled when requesting a resource with a non-allowed methodaiohttp · aiohttp · CWE-772 | High8.7 | — | 0.6% | Nov 18, 2024 |
30Monitor | CVE-2023-37276No exploit | aiohttp vulnerable to HTTP request smugglingaiohttp · aiohttp · CWE-444 | High7.5 | — | 1.3% | Jul 19, 2023 |
30Monitor | CVE-2024-30251No exploit | Denial of service when trying to parse malformed POST requests in aiohttpaiohttp · aiohttp · CWE-835 | High7.5 | — | 1.1% | May 2, 2024 |
30Monitor | CVE-2023-47627No exploit | Request smuggling in aiohttpaiohttp · aiohttp · CWE-444 | High7.5 | — | 0.9% | Nov 14, 2023 |
30Monitor | CVE-2025-69223No exploit | AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bombaiohttp · aiohttp · CWE-409 | High7.5 | — | 0.6% | Jan 5, 2026 |
29Monitor | CVE-2026-34993No exploit | AIOHTTP Vulnerable to Deserialization of Untrusted Dataaiohttp · aiohttp · CWE-502 | High7.3 | — | 0.5% | Jun 2, 2026 |
27Monitor | CVE-2026-22815No exploit | AIOHTTP: Uncapped memory usage possible through aiohttp allowing unlimited trailer headersaiohttp · aiohttp · CWE-400 | Medium6.9 | — | 0.4% | Apr 1, 2026 |
26Monitor | CVE-2024-23829No exploit | aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separatorsaiohttp · aiohttp · CWE-444 | Medium6.5 | — | 1.0% | Jan 29, 2024 |
26Monitor | CVE-2023-47641No exploit | Inconsistent interpretation of `Content-Length` vs. `Transfer-Encoding` in aiohttpaiohttp · aiohttp · CWE-444 | Medium6.5 | — | 0.8% | Nov 14, 2023 |
26Monitor | CVE-2026-34516No exploit | AIOHTTP: Multipart Header Size Bypassaiohttp · aiohttp · CWE-770 | Medium6.6 | — | 0.6% | Apr 1, 2026 |
26Monitor | CVE-2026-54277No exploit | AIOHTTP: C HTTP Parser Bypasses max_line_size for Fragmented Linesaiohttp · aiohttp · CWE-770 | Medium6.6 | — | 0.6% | Jun 22, 2026 |
26Monitor | CVE-2026-54274No exploit | AIOHTTP: Incomplete websocket frame payloads bypass memory limitsaiohttp · aiohttp · CWE-770 | Medium6.6 | — | 0.5% | Jun 22, 2026 |
26Monitor | CVE-2026-34515No exploit | AIOHTTP: UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windowsaiohttp · aiohttp · CWE-36 | Medium6.6 | — | 0.5% | Apr 1, 2026 |
26Monitor | CVE-2026-54273No exploit | AIOHTTP: HTTP/1 Pipelined Requests Queue Without Limitaiohttp · aiohttp · CWE-770 | Medium6.6 | — | 0.5% | Jun 22, 2026 |
26Monitor | CVE-2026-54278No exploit | AIOHTTP: Unread Compressed Request Bodies Bypass client_max_size During Cleanupaiohttp · aiohttp · CWE-409 | Medium6.6 | — | 0.5% | Jun 22, 2026 |
26Monitor | CVE-2025-69228No exploit | AIOHTTP vulnerable to denial of service through large payloadsaiohttp · aiohttp · CWE-770 | Medium6.6 | — | 0.4% | Jan 5, 2026 |
26Monitor | CVE-2025-69229No exploit | AIOHTTP vulnerable to DoS through chunked messagesaiohttp · aiohttp · CWE-770 | Medium6.6 | — | 0.4% | Jan 5, 2026 |
26Monitor | CVE-2025-69227No exploit | AIOHTTP vulnerable to DoS when bypassing assertsaiohttp · aiohttp · CWE-835 | Medium6.6 | — | 0.4% | Jan 5, 2026 |
26Monitor | CVE-2026-47265No exploit | AIOHTTP vulnerable to cross-origin redirect with per-request cookiesaiohttp · aiohttp · CWE-346 | Medium6.6 | — | 0.2% | Jun 2, 2026 |
25Monitor | CVE-2021-21330No exploit | Open redirect vulnerability in aiohttpaiohttp · aiohttp · CWE-601 | Medium6.1 | — | 1.9% | Feb 25, 2021 |
25Monitor | CVE-2024-52304No exploit | aiohttp vulnerable to request smuggling due to incorrect parsing of chunk extensionsaiohttp · aiohttp · CWE-444 | Medium6.3 | — | 0.6% | Nov 18, 2024 |
25Monitor | CVE-2026-34525No exploit | AIOHTTP: Duplicate Host header acceptedaiohttp · aiohttp · CWE-20 | Medium6.3 | — | 0.4% | Apr 1, 2026 |
25Monitor | CVE-2025-69226No exploit | AIOHTTP allows for a brute-force leak of internal static filepath componentsaiohttp · aiohttp · CWE-22 | Medium6.3 | — | 0.4% | Jan 5, 2026 |
25Monitor | CVE-2026-54276No exploit | AIOHTTP: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challengesaiohttp · aiohttp · CWE-200 | Medium6.3 | — | 0.3% | Jun 22, 2026 |
- CVE-2024-2333453Plan
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
HighCVSS 7.5Proof of conceptEPSS 77%aiohttp · aiohttpJan 29, 2024
- CVE-2024-5230334Monitor
aiohttp memory leak when middleware is enabled when requesting a resource with a non-allowed method
HighCVSS 8.7No exploitEPSS 1%aiohttp · aiohttpNov 18, 2024
- CVE-2023-3727630Monitor
aiohttp vulnerable to HTTP request smuggling
HighCVSS 7.5No exploitEPSS 1%aiohttp · aiohttpJul 19, 2023
- CVE-2024-3025130Monitor
Denial of service when trying to parse malformed POST requests in aiohttp
HighCVSS 7.5No exploitEPSS 1%aiohttp · aiohttpMay 2, 2024
- CVE-2023-4762730Monitor
Request smuggling in aiohttp
HighCVSS 7.5No exploitEPSS 1%aiohttp · aiohttpNov 14, 2023
- CVE-2025-6922330Monitor
AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
HighCVSS 7.5No exploitEPSS 1%aiohttp · aiohttpJan 5, 2026
- CVE-2026-3499329Monitor
AIOHTTP Vulnerable to Deserialization of Untrusted Data
HighCVSS 7.3No exploitEPSS 0%aiohttp · aiohttpJun 2, 2026
- CVE-2026-2281527Monitor
AIOHTTP: Uncapped memory usage possible through aiohttp allowing unlimited trailer headers
MediumCVSS 6.9No exploitEPSS 0%aiohttp · aiohttpApr 1, 2026
- CVE-2024-2382926Monitor
aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators
MediumCVSS 6.5No exploitEPSS 1%aiohttp · aiohttpJan 29, 2024
- CVE-2023-4764126Monitor
Inconsistent interpretation of `Content-Length` vs. `Transfer-Encoding` in aiohttp
MediumCVSS 6.5No exploitEPSS 1%aiohttp · aiohttpNov 14, 2023
- CVE-2026-3451626Monitor
AIOHTTP: Multipart Header Size Bypass
MediumCVSS 6.6No exploitEPSS 1%aiohttp · aiohttpApr 1, 2026
- CVE-2026-5427726Monitor
AIOHTTP: C HTTP Parser Bypasses max_line_size for Fragmented Lines
MediumCVSS 6.6No exploitEPSS 1%aiohttp · aiohttpJun 22, 2026
- CVE-2026-5427426Monitor
AIOHTTP: Incomplete websocket frame payloads bypass memory limits
MediumCVSS 6.6No exploitEPSS 1%aiohttp · aiohttpJun 22, 2026
- CVE-2026-3451526Monitor
AIOHTTP: UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows
MediumCVSS 6.6No exploitEPSS 0%aiohttp · aiohttpApr 1, 2026
- CVE-2026-5427326Monitor
AIOHTTP: HTTP/1 Pipelined Requests Queue Without Limit
MediumCVSS 6.6No exploitEPSS 0%aiohttp · aiohttpJun 22, 2026
- CVE-2026-5427826Monitor
AIOHTTP: Unread Compressed Request Bodies Bypass client_max_size During Cleanup
MediumCVSS 6.6No exploitEPSS 0%aiohttp · aiohttpJun 22, 2026
- CVE-2025-6922826Monitor
AIOHTTP vulnerable to denial of service through large payloads
MediumCVSS 6.6No exploitEPSS 0%aiohttp · aiohttpJan 5, 2026
- CVE-2025-6922926Monitor
AIOHTTP vulnerable to DoS through chunked messages
MediumCVSS 6.6No exploitEPSS 0%aiohttp · aiohttpJan 5, 2026
- CVE-2025-6922726Monitor
AIOHTTP vulnerable to DoS when bypassing asserts
MediumCVSS 6.6No exploitEPSS 0%aiohttp · aiohttpJan 5, 2026
- CVE-2026-4726526Monitor
AIOHTTP vulnerable to cross-origin redirect with per-request cookies
MediumCVSS 6.6No exploitEPSS 0%aiohttp · aiohttpJun 2, 2026
- CVE-2021-2133025Monitor
Open redirect vulnerability in aiohttp
MediumCVSS 6.1No exploitEPSS 2%aiohttp · aiohttpFeb 25, 2021
- CVE-2024-5230425Monitor
aiohttp vulnerable to request smuggling due to incorrect parsing of chunk extensions
MediumCVSS 6.3No exploitEPSS 1%aiohttp · aiohttpNov 18, 2024
- CVE-2026-3452525Monitor
AIOHTTP: Duplicate Host header accepted
MediumCVSS 6.3No exploitEPSS 0%aiohttp · aiohttpApr 1, 2026
- CVE-2025-6922625Monitor
AIOHTTP allows for a brute-force leak of internal static filepath components
MediumCVSS 6.3No exploitEPSS 0%aiohttp · aiohttpJan 5, 2026
- CVE-2026-5427625Monitor
AIOHTTP: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges
MediumCVSS 6.3No exploitEPSS 0%aiohttp · aiohttpJun 22, 2026