Where
-Infinity
0

pip/aiohttpAIOHTTP: Incomplete websocket frame payloads bypass memory limits

Risk 43
Severity
6.6
First published (updated )

pip/aiohttpAIOHTTP: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections

Risk 43
Severity
2.7
First published (updated )

pip/aiohttpAIOHTTP: Payload Response Resources Are Not Closed After Mid-Body Disconnect

Risk 43
Severity
1.7
First published (updated )

pip/aiohttpAIOHTTP: HTTP/1 Pipelined Requests Queue Without Limit

Risk 43
Severity
6.6
First published (updated )

pip/aiohttpAIOHTTP: Unread Compressed Request Bodies Bypass client_max_size During Cleanup

Risk 43
Severity
6.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/aiohttpAIOHTTP: C HTTP Parser Bypasses max_line_size for Fragmented Lines

Risk 43
Severity
6.6
First published (updated )

pip/aiohttpAIOHTTP: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges

Risk 29
Severity
6.3
First published (updated )

pip/aiohttpAIOHTTP: Host-Only Cookies Become Domain Cookies After CookieJar Persistence

Risk 43
Severity
1.3
First published (updated )

pip/aiohttpAIOHTTP: CRLF injection in multipart headers

Risk 43
Severity
2.7
First published (updated )

aiohttp aiohttpAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.1…

Risk 33
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pypi/aiohttpAIOHTTP vulnerable to cross-origin redirect with per-request cookies

Risk 43
Severity
6.6
First published (updated )

pypi/aiohttpAIOHTTP Vulnerable to Deserialization of Untrusted Data

Risk 64
Severity
7.3
First published (updated )

pip/aiohttpAIOHTTP: Duplicate Host header accepted

Risk 37
Severity
6.3
First published (updated )

pip/aiohttpAIOHTTP: C parser (llhttp) accepts null bytes and control characters in response header values - header injection / security bypass

Risk 66
Severity
2.7
First published (updated )

pip/aiohttpAIOHTTP: HTTP response splitting via \r in reason phrase

Risk 27
Severity
2.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/aiohttpAIOHTTP: Cookie and Proxy-Authorization headers leaked on cross-origin redirect

Risk 27
Severity
2.7
First published (updated )

pip/aiohttpAIOHTTP: Late size enforcement for non-file multipart fields causes memory DoS

Risk 27
Severity
2.7
First published (updated )

pip/aiohttpAIOHTTP: Multipart Header Size Bypass

Risk 43
Severity
6.6
First published (updated )

pip/aiohttpAIOHTTP: UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows

Risk 43
Severity
6.6
First published (updated )

pip/aiohttpAIOHTTP: CRLF injection in multipart part content type header construction

Risk 27
Severity
2.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/aiohttpAIOHTTP: Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector

Risk 43
Severity
2.7
First published (updated )

pip/aiohttpAIOHTTP: Uncapped memory usage possible through aiohttp allowing unlimited trailer headers

Risk 43
Severity
6.9
First published (updated )

pip/aiohttpAIOHTTP Vulnerable to Cookie Parser Warning Storm

Risk 29
Severity
2.7
First published (updated )

pip/aiohttpAIOHTTP vulnerable to DoS through chunked messages

Risk 43
Severity
6.6
First published (updated )

pip/aiohttpAIOHTTP vulnerable to denial of service through large payloads

Risk 46
Severity
6.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pypi/aiohttpAIOHTTP vulnerable to DoS when bypassing asserts

Risk 46
Severity
6.6
First published (updated )

pypi/aiohttpAIOHTTP Regex Mismatch Allows Unicode in ASCII-Only Protocol Fields

Risk 29
Severity
2.7
First published (updated )

pypi/aiohttpAIOHTTP allows for a brute-force leak of internal static filepath components

Risk 31
Severity
6.3
First published (updated )

pypi/aiohttpAIOHTTP's Unicode processing of header values could cause parsing discrepancies

Risk 42
Severity
6.5
First published (updated )

pypi/aiohttpAIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb

Risk 46
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203