Launch Week Day 1: Announcing Security Design Review
45 Total advisories
45 Vulnerabilities
0 Malware

Vulnerabilities

MEDIUM 5.5
PyPI

CVE-2022-33124

Withdrawn: Denial of Service in aiohttp

MEDIUM 5.5
PyPI

CVE-2022-33124

CVE-2022-33124

MEDIUM 6.4
PyPI

CVE-2026-34993

AIOHTTP is Vulnerable to Deserialization of Untrusted Data

UNKNOWN
PyPI

CVE-2026-47265

AIOHTTP is vulnerable to cross-origin redirect with per-request cookies

MEDIUM 5.3
PyPI

CVE-2026-34518

AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect

CRITICAL 9.1
PyPI

CVE-2026-34520

AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass

HIGH 7.5
PyPI

CVE-2026-34516

AIOHTTP has a Multipart Header Size Bypass

UNKNOWN
PyPI

CVE-2026-22815

aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage

UNKNOWN
PyPI

CVE-2026-34515

AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows

UNKNOWN
PyPI

CVE-2026-34514

AIOHTTP has CRLF injection through multipart part content type header construction

UNKNOWN
PyPI

CVE-2026-34513

AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector

UNKNOWN
PyPI

CVE-2026-34525

AIOHTTP accepts duplicate Host headers

UNKNOWN
PyPI

CVE-2026-34519

AIOHTTP has HTTP response splitting via \r in reason phrase

UNKNOWN
PyPI

CVE-2026-34517

AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS

LOW 3.1
PyPI

CVE-2021-21330

`aiohttp` Open Redirect vulnerability (`normalize_path_middleware` middleware)

MEDIUM 5.9
PyPI

CVE-2024-23334

aiohttp is vulnerable to directory traversal

MEDIUM 5.3
PyPI

CVE-2023-49082

aiohttp's ClientSession is vulnerable to CRLF injection via method

UNKNOWN
PyPI

CVE-2025-69224

AIOHTTP's unicode processing of header values could cause parsing discrepancies

HIGH 7.5
PyPI

CVE-2024-30251

aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests

UNKNOWN
PyPI

CVE-2025-69226

AIOHTTP vulnerable to brute-force leak of internal static file path components

HIGH 7.2
PyPI

CVE-2023-49081

aiohttp's ClientSession is vulnerable to CRLF injection via version

UNKNOWN
PyPI

CVE-2025-69230

AIOHTTP Vulnerable to Cookie Parser Warning Storm

UNKNOWN
PyPI

GHSA-pjjw-qhg8-p2p9

aiohttp has vulnerable dependency that is vulnerable to request smuggling

UNKNOWN
PyPI

CVE-2025-53643

AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections

MEDIUM 6.5
PyPI

CVE-2024-23829

aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators

MEDIUM 5.3
PyPI

CVE-2023-47627

AIOHTTP has problems in HTTP parser (the python one, not llhttp)

UNKNOWN
PyPI

CVE-2025-69227

AIOHTTP vulnerable to DoS when bypassing asserts

UNKNOWN
PyPI

CVE-2024-52304

aiohttp allows request smuggling due to incorrect parsing of chunk extensions

HIGH 7.5
PyPI

CVE-2025-69223

AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb

UNKNOWN
PyPI

CVE-2025-69225

AIOHTTP has unicode match groups in regexes for ASCII protocol elements

MEDIUM 4.8
PyPI

CVE-2024-42367

In aiohttp, compressed files as symlinks are not protected from path traversal

HIGH 7.5
PyPI

CVE-2024-52303

aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method

MEDIUM 6.1
PyPI

CVE-2024-27306

aiohttp Cross-site Scripting vulnerability on index pages for static file handling

UNKNOWN
PyPI

CVE-2025-69228

AIOHTTP vulnerable to denial of service through large payloads

UNKNOWN
PyPI

CVE-2025-69229

AIOHTTP vulnerable to DoS through chunked messages

LOW 3.4
PyPI

CVE-2023-47641

Aiohttp has inconsistent interpretation of `Content-Length` vs. `Transfer-Encoding` differing in C and Python fallbacks

MEDIUM 5.3
PyPI

CVE-2023-37276

aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parser

MEDIUM 6.5
PyPI

CVE-2024-23829

CVE-2024-23829

HIGH 7.5
PyPI

CVE-2024-23334

CVE-2024-23334

MEDIUM 5.3
PyPI

CVE-2023-49081

CVE-2023-49081

MEDIUM 5.3
PyPI

CVE-2023-49082

CVE-2023-49082

HIGH 7.5
PyPI

CVE-2023-47627

CVE-2023-47627

MEDIUM 6.5
PyPI

CVE-2023-47641

CVE-2023-47641

UNKNOWN
PyPI

CVE-2023-37276

aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parser

UNKNOWN
PyPI

CVE-2021-21330

CVE-2021-21330

Ready to move

Start Securing

Free, no credit card | First findings in minutes