Launch Week Day 1: Announcing Security Design Review
UNKNOWN PyPI

aiohttp has vulnerable dependency that is vulnerable to request smuggling

GHSA-pjjw-qhg8-p2p9

Published ยท Modified

Description

Summary

llhttp 8.1.1 is vulnerable to two request smuggling vulnerabilities.
Details have not been disclosed yet, so refer to llhttp for future information.
The issue is resolved by using llhttp 9+ (which is included in aiohttp 3.8.6+).

Ready to move

Start Securing

Free, no credit card | First findings in minutes