Skip to content
Noroxi

aiohttp records

44 published records for vendor aiohttp.

All records

44 records
  • aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal

    HighCVSS 7.5Proof of conceptEPSS 77%

    aiohttp · aiohttpJan 29, 2024

  • aiohttp memory leak when middleware is enabled when requesting a resource with a non-allowed method

    HighCVSS 8.7No exploitEPSS 1%

    aiohttp · aiohttpNov 18, 2024

  • aiohttp vulnerable to HTTP request smuggling

    HighCVSS 7.5No exploitEPSS 1%

    aiohttp · aiohttpJul 19, 2023

  • Denial of service when trying to parse malformed POST requests in aiohttp

    HighCVSS 7.5No exploitEPSS 1%

    aiohttp · aiohttpMay 2, 2024

  • Request smuggling in aiohttp

    HighCVSS 7.5No exploitEPSS 1%

    aiohttp · aiohttpNov 14, 2023

  • AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb

    HighCVSS 7.5No exploitEPSS 1%

    aiohttp · aiohttpJan 5, 2026

  • AIOHTTP Vulnerable to Deserialization of Untrusted Data

    HighCVSS 7.3No exploitEPSS 0%

    aiohttp · aiohttpJun 2, 2026

  • AIOHTTP: Uncapped memory usage possible through aiohttp allowing unlimited trailer headers

    MediumCVSS 6.9No exploitEPSS 0%

    aiohttp · aiohttpApr 1, 2026

  • aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators

    MediumCVSS 6.5No exploitEPSS 1%

    aiohttp · aiohttpJan 29, 2024

  • Inconsistent interpretation of `Content-Length` vs. `Transfer-Encoding` in aiohttp

    MediumCVSS 6.5No exploitEPSS 1%

    aiohttp · aiohttpNov 14, 2023

  • AIOHTTP: Multipart Header Size Bypass

    MediumCVSS 6.6No exploitEPSS 1%

    aiohttp · aiohttpApr 1, 2026

  • AIOHTTP: C HTTP Parser Bypasses max_line_size for Fragmented Lines

    MediumCVSS 6.6No exploitEPSS 1%

    aiohttp · aiohttpJun 22, 2026

  • AIOHTTP: Incomplete websocket frame payloads bypass memory limits

    MediumCVSS 6.6No exploitEPSS 1%

    aiohttp · aiohttpJun 22, 2026

  • AIOHTTP: UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows

    MediumCVSS 6.6No exploitEPSS 0%

    aiohttp · aiohttpApr 1, 2026

  • AIOHTTP: HTTP/1 Pipelined Requests Queue Without Limit

    MediumCVSS 6.6No exploitEPSS 0%

    aiohttp · aiohttpJun 22, 2026

  • AIOHTTP: Unread Compressed Request Bodies Bypass client_max_size During Cleanup

    MediumCVSS 6.6No exploitEPSS 0%

    aiohttp · aiohttpJun 22, 2026

  • AIOHTTP vulnerable to denial of service through large payloads

    MediumCVSS 6.6No exploitEPSS 0%

    aiohttp · aiohttpJan 5, 2026

  • AIOHTTP vulnerable to DoS through chunked messages

    MediumCVSS 6.6No exploitEPSS 0%

    aiohttp · aiohttpJan 5, 2026

  • AIOHTTP vulnerable to DoS when bypassing asserts

    MediumCVSS 6.6No exploitEPSS 0%

    aiohttp · aiohttpJan 5, 2026

  • AIOHTTP vulnerable to cross-origin redirect with per-request cookies

    MediumCVSS 6.6No exploitEPSS 0%

    aiohttp · aiohttpJun 2, 2026

  • Open redirect vulnerability in aiohttp

    MediumCVSS 6.1No exploitEPSS 2%

    aiohttp · aiohttpFeb 25, 2021

  • aiohttp vulnerable to request smuggling due to incorrect parsing of chunk extensions

    MediumCVSS 6.3No exploitEPSS 1%

    aiohttp · aiohttpNov 18, 2024

  • AIOHTTP: Duplicate Host header accepted

    MediumCVSS 6.3No exploitEPSS 0%

    aiohttp · aiohttpApr 1, 2026

  • AIOHTTP allows for a brute-force leak of internal static filepath components

    MediumCVSS 6.3No exploitEPSS 0%

    aiohttp · aiohttpJan 5, 2026

  • AIOHTTP: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges

    MediumCVSS 6.3No exploitEPSS 0%

    aiohttp · aiohttpJun 22, 2026