aiohttp kayıtları
aiohttp üreticisine ait 44 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %97,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')8
- CWE-770 Allocation of Resources Without Limits or Throttling8
- CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')3
- CWE-20 Improper Input Validation3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
44 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
53Planlayın | CVE-2024-23334Kavram kanıtı | aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversalaiohttp · aiohttp · CWE-22 | Yüksek7,5 | — | %76,9 | 29 Oca 2024 |
34İzleyin | CVE-2024-52303İstismar yok | aiohttp memory leak when middleware is enabled when requesting a resource with a non-allowed methodaiohttp · aiohttp · CWE-772 | Yüksek8,7 | — | %0,6 | 18 Kas 2024 |
30İzleyin | CVE-2023-37276İstismar yok | aiohttp vulnerable to HTTP request smugglingaiohttp · aiohttp · CWE-444 | Yüksek7,5 | — | %1,3 | 19 Tem 2023 |
30İzleyin | CVE-2024-30251İstismar yok | Denial of service when trying to parse malformed POST requests in aiohttpaiohttp · aiohttp · CWE-835 | Yüksek7,5 | — | %1,1 | 2 May 2024 |
30İzleyin | CVE-2023-47627İstismar yok | Request smuggling in aiohttpaiohttp · aiohttp · CWE-444 | Yüksek7,5 | — | %0,9 | 14 Kas 2023 |
30İzleyin | CVE-2025-69223İstismar yok | AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bombaiohttp · aiohttp · CWE-409 | Yüksek7,5 | — | %0,6 | 5 Oca 2026 |
29İzleyin | CVE-2026-34993İstismar yok | AIOHTTP Vulnerable to Deserialization of Untrusted Dataaiohttp · aiohttp · CWE-502 | Yüksek7,3 | — | %0,5 | 2 Haz 2026 |
27İzleyin | CVE-2026-22815İstismar yok | AIOHTTP: Uncapped memory usage possible through aiohttp allowing unlimited trailer headersaiohttp · aiohttp · CWE-400 | Orta6,9 | — | %0,4 | 1 Nis 2026 |
26İzleyin | CVE-2024-23829İstismar yok | aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separatorsaiohttp · aiohttp · CWE-444 | Orta6,5 | — | %1,0 | 29 Oca 2024 |
26İzleyin | CVE-2023-47641İstismar yok | Inconsistent interpretation of `Content-Length` vs. `Transfer-Encoding` in aiohttpaiohttp · aiohttp · CWE-444 | Orta6,5 | — | %0,8 | 14 Kas 2023 |
26İzleyin | CVE-2026-34516İstismar yok | AIOHTTP: Multipart Header Size Bypassaiohttp · aiohttp · CWE-770 | Orta6,6 | — | %0,6 | 1 Nis 2026 |
26İzleyin | CVE-2026-54277İstismar yok | AIOHTTP: C HTTP Parser Bypasses max_line_size for Fragmented Linesaiohttp · aiohttp · CWE-770 | Orta6,6 | — | %0,6 | 22 Haz 2026 |
26İzleyin | CVE-2026-54274İstismar yok | AIOHTTP: Incomplete websocket frame payloads bypass memory limitsaiohttp · aiohttp · CWE-770 | Orta6,6 | — | %0,5 | 22 Haz 2026 |
26İzleyin | CVE-2026-34515İstismar yok | AIOHTTP: UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windowsaiohttp · aiohttp · CWE-36 | Orta6,6 | — | %0,5 | 1 Nis 2026 |
26İzleyin | CVE-2026-54273İstismar yok | AIOHTTP: HTTP/1 Pipelined Requests Queue Without Limitaiohttp · aiohttp · CWE-770 | Orta6,6 | — | %0,5 | 22 Haz 2026 |
26İzleyin | CVE-2026-54278İstismar yok | AIOHTTP: Unread Compressed Request Bodies Bypass client_max_size During Cleanupaiohttp · aiohttp · CWE-409 | Orta6,6 | — | %0,5 | 22 Haz 2026 |
26İzleyin | CVE-2025-69228İstismar yok | AIOHTTP vulnerable to denial of service through large payloadsaiohttp · aiohttp · CWE-770 | Orta6,6 | — | %0,4 | 5 Oca 2026 |
26İzleyin | CVE-2025-69229İstismar yok | AIOHTTP vulnerable to DoS through chunked messagesaiohttp · aiohttp · CWE-770 | Orta6,6 | — | %0,4 | 5 Oca 2026 |
26İzleyin | CVE-2025-69227İstismar yok | AIOHTTP vulnerable to DoS when bypassing assertsaiohttp · aiohttp · CWE-835 | Orta6,6 | — | %0,4 | 5 Oca 2026 |
26İzleyin | CVE-2026-47265İstismar yok | AIOHTTP vulnerable to cross-origin redirect with per-request cookiesaiohttp · aiohttp · CWE-346 | Orta6,6 | — | %0,2 | 2 Haz 2026 |
25İzleyin | CVE-2021-21330İstismar yok | Open redirect vulnerability in aiohttpaiohttp · aiohttp · CWE-601 | Orta6,1 | — | %1,9 | 25 Şub 2021 |
25İzleyin | CVE-2024-52304İstismar yok | aiohttp vulnerable to request smuggling due to incorrect parsing of chunk extensionsaiohttp · aiohttp · CWE-444 | Orta6,3 | — | %0,6 | 18 Kas 2024 |
25İzleyin | CVE-2026-34525İstismar yok | AIOHTTP: Duplicate Host header acceptedaiohttp · aiohttp · CWE-20 | Orta6,3 | — | %0,4 | 1 Nis 2026 |
25İzleyin | CVE-2025-69226İstismar yok | AIOHTTP allows for a brute-force leak of internal static filepath componentsaiohttp · aiohttp · CWE-22 | Orta6,3 | — | %0,4 | 5 Oca 2026 |
25İzleyin | CVE-2026-54276İstismar yok | AIOHTTP: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challengesaiohttp · aiohttp · CWE-200 | Orta6,3 | — | %0,3 | 22 Haz 2026 |
- CVE-2024-2333453Planlayın
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
YüksekCVSS 7,5Kavram kanıtıEPSS %77aiohttp · aiohttp29 Oca 2024
- CVE-2024-5230334İzleyin
aiohttp memory leak when middleware is enabled when requesting a resource with a non-allowed method
YüksekCVSS 8,7İstismar yokEPSS %1aiohttp · aiohttp18 Kas 2024
- CVE-2023-3727630İzleyin
aiohttp vulnerable to HTTP request smuggling
YüksekCVSS 7,5İstismar yokEPSS %1aiohttp · aiohttp19 Tem 2023
- CVE-2024-3025130İzleyin
Denial of service when trying to parse malformed POST requests in aiohttp
YüksekCVSS 7,5İstismar yokEPSS %1aiohttp · aiohttp2 May 2024
- CVE-2023-4762730İzleyin
Request smuggling in aiohttp
YüksekCVSS 7,5İstismar yokEPSS %1aiohttp · aiohttp14 Kas 2023
- CVE-2025-6922330İzleyin
AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
YüksekCVSS 7,5İstismar yokEPSS %1aiohttp · aiohttp5 Oca 2026
- CVE-2026-3499329İzleyin
AIOHTTP Vulnerable to Deserialization of Untrusted Data
YüksekCVSS 7,3İstismar yokEPSS %0aiohttp · aiohttp2 Haz 2026
- CVE-2026-2281527İzleyin
AIOHTTP: Uncapped memory usage possible through aiohttp allowing unlimited trailer headers
OrtaCVSS 6,9İstismar yokEPSS %0aiohttp · aiohttp1 Nis 2026
- CVE-2024-2382926İzleyin
aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators
OrtaCVSS 6,5İstismar yokEPSS %1aiohttp · aiohttp29 Oca 2024
- CVE-2023-4764126İzleyin
Inconsistent interpretation of `Content-Length` vs. `Transfer-Encoding` in aiohttp
OrtaCVSS 6,5İstismar yokEPSS %1aiohttp · aiohttp14 Kas 2023
- CVE-2026-3451626İzleyin
AIOHTTP: Multipart Header Size Bypass
OrtaCVSS 6,6İstismar yokEPSS %1aiohttp · aiohttp1 Nis 2026
- CVE-2026-5427726İzleyin
AIOHTTP: C HTTP Parser Bypasses max_line_size for Fragmented Lines
OrtaCVSS 6,6İstismar yokEPSS %1aiohttp · aiohttp22 Haz 2026
- CVE-2026-5427426İzleyin
AIOHTTP: Incomplete websocket frame payloads bypass memory limits
OrtaCVSS 6,6İstismar yokEPSS %1aiohttp · aiohttp22 Haz 2026
- CVE-2026-3451526İzleyin
AIOHTTP: UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows
OrtaCVSS 6,6İstismar yokEPSS %0aiohttp · aiohttp1 Nis 2026
- CVE-2026-5427326İzleyin
AIOHTTP: HTTP/1 Pipelined Requests Queue Without Limit
OrtaCVSS 6,6İstismar yokEPSS %0aiohttp · aiohttp22 Haz 2026
- CVE-2026-5427826İzleyin
AIOHTTP: Unread Compressed Request Bodies Bypass client_max_size During Cleanup
OrtaCVSS 6,6İstismar yokEPSS %0aiohttp · aiohttp22 Haz 2026
- CVE-2025-6922826İzleyin
AIOHTTP vulnerable to denial of service through large payloads
OrtaCVSS 6,6İstismar yokEPSS %0aiohttp · aiohttp5 Oca 2026
- CVE-2025-6922926İzleyin
AIOHTTP vulnerable to DoS through chunked messages
OrtaCVSS 6,6İstismar yokEPSS %0aiohttp · aiohttp5 Oca 2026
- CVE-2025-6922726İzleyin
AIOHTTP vulnerable to DoS when bypassing asserts
OrtaCVSS 6,6İstismar yokEPSS %0aiohttp · aiohttp5 Oca 2026
- CVE-2026-4726526İzleyin
AIOHTTP vulnerable to cross-origin redirect with per-request cookies
OrtaCVSS 6,6İstismar yokEPSS %0aiohttp · aiohttp2 Haz 2026
- CVE-2021-2133025İzleyin
Open redirect vulnerability in aiohttp
OrtaCVSS 6,1İstismar yokEPSS %2aiohttp · aiohttp25 Şub 2021
- CVE-2024-5230425İzleyin
aiohttp vulnerable to request smuggling due to incorrect parsing of chunk extensions
OrtaCVSS 6,3İstismar yokEPSS %1aiohttp · aiohttp18 Kas 2024
- CVE-2026-3452525İzleyin
AIOHTTP: Duplicate Host header accepted
OrtaCVSS 6,3İstismar yokEPSS %0aiohttp · aiohttp1 Nis 2026
- CVE-2025-6922625İzleyin
AIOHTTP allows for a brute-force leak of internal static filepath components
OrtaCVSS 6,3İstismar yokEPSS %0aiohttp · aiohttp5 Oca 2026
- CVE-2026-5427625İzleyin
AIOHTTP: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges
OrtaCVSS 6,3İstismar yokEPSS %0aiohttp · aiohttp22 Haz 2026