45 Total advisories
45 Vulnerabilities
0 Malware
Vulnerabilities
MEDIUM 5.5
CVE-2022-33124
Withdrawn: Denial of Service in aiohttp
MEDIUM 5.5
CVE-2022-33124
CVE-2022-33124
MEDIUM 6.4
CVE-2026-34993
AIOHTTP is Vulnerable to Deserialization of Untrusted Data
UNKNOWN
CVE-2026-47265
AIOHTTP is vulnerable to cross-origin redirect with per-request cookies
MEDIUM 5.3
CVE-2026-34518
AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect
CRITICAL 9.1
CVE-2026-34520
AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass
HIGH 7.5
CVE-2026-34516
AIOHTTP has a Multipart Header Size Bypass
UNKNOWN
CVE-2026-22815
aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage
UNKNOWN
CVE-2026-34515
AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows
UNKNOWN
CVE-2026-34514
AIOHTTP has CRLF injection through multipart part content type header construction
UNKNOWN
CVE-2026-34513
AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector
UNKNOWN
CVE-2026-34525
AIOHTTP accepts duplicate Host headers
UNKNOWN
CVE-2026-34519
AIOHTTP has HTTP response splitting via \r in reason phrase
UNKNOWN
CVE-2026-34517
AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS
LOW 3.1
CVE-2021-21330
`aiohttp` Open Redirect vulnerability (`normalize_path_middleware` middleware)
MEDIUM 5.9
CVE-2024-23334
aiohttp is vulnerable to directory traversal
MEDIUM 5.3
CVE-2023-49082
aiohttp's ClientSession is vulnerable to CRLF injection via method
UNKNOWN
CVE-2025-69224
AIOHTTP's unicode processing of header values could cause parsing discrepancies
HIGH 7.5
CVE-2024-30251
aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests
UNKNOWN
CVE-2025-69226
AIOHTTP vulnerable to brute-force leak of internal static file path components
HIGH 7.2
CVE-2023-49081
aiohttp's ClientSession is vulnerable to CRLF injection via version
UNKNOWN
CVE-2025-69230
AIOHTTP Vulnerable to Cookie Parser Warning Storm
UNKNOWN
GHSA-pjjw-qhg8-p2p9
aiohttp has vulnerable dependency that is vulnerable to request smuggling
UNKNOWN
CVE-2025-53643
AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
MEDIUM 6.5
CVE-2024-23829
aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators
MEDIUM 5.3
CVE-2023-47627
AIOHTTP has problems in HTTP parser (the python one, not llhttp)
UNKNOWN
CVE-2025-69227
AIOHTTP vulnerable to DoS when bypassing asserts
UNKNOWN
CVE-2024-52304
aiohttp allows request smuggling due to incorrect parsing of chunk extensions
HIGH 7.5
CVE-2025-69223
AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
UNKNOWN
CVE-2025-69225
AIOHTTP has unicode match groups in regexes for ASCII protocol elements
MEDIUM 4.8
CVE-2024-42367
In aiohttp, compressed files as symlinks are not protected from path traversal
HIGH 7.5
CVE-2024-52303
aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method
MEDIUM 6.1
CVE-2024-27306
aiohttp Cross-site Scripting vulnerability on index pages for static file handling
UNKNOWN
CVE-2025-69228
AIOHTTP vulnerable to denial of service through large payloads
UNKNOWN
CVE-2025-69229
AIOHTTP vulnerable to DoS through chunked messages
LOW 3.4
CVE-2023-47641
Aiohttp has inconsistent interpretation of `Content-Length` vs. `Transfer-Encoding` differing in C and Python fallbacks
MEDIUM 5.3
CVE-2023-37276
aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parser
MEDIUM 6.5
CVE-2024-23829
CVE-2024-23829
HIGH 7.5
CVE-2024-23334
CVE-2024-23334
MEDIUM 5.3
CVE-2023-49081
CVE-2023-49081
MEDIUM 5.3
CVE-2023-49082
CVE-2023-49082
HIGH 7.5
CVE-2023-47627
CVE-2023-47627
MEDIUM 6.5
CVE-2023-47641
CVE-2023-47641
UNKNOWN
CVE-2023-37276
aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parser
UNKNOWN
CVE-2021-21330
CVE-2021-21330
Ready to move
Start Securing
Free, no credit card | First findings in minutes