Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2242769
AlmaLinux
5975
Alpaquita
16176
Alpine
4655
Android
3708
Azure Linux
17971
BellSoft Hardened Containers
770
Bitnami
9501
Chainguard
1048720
CleanStart
5432
CRAN
14
crates.io
2768
Debian
68992
Echo
7853
GHC
3
GIT
109121
GitHub Actions
55
Go
9332
Hackage
33
Hex
365
Julia
1713
Linux
29975
Mageia
6237
Maven
7055
MinimOS
148659
npm
229271
NuGet
1869
opam
29
openEuler
8900
openSUSE
14647
OSS-Fuzz
4019
Packagist
7103
Pub
11
PyPI
25495
Red Hat
23535
Rocky Linux
4344
Root
19650
RubyGems
5369
SUSE
23455
SwiftURL
61
TuxCare
9974
Ubuntu
66090
VSCode
21
Wolfi
293843
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3545
PyPI/aiohttp
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
04 Aug
Fix available
Severity - 7.1 (High)
PYSEC-2026-3546
PyPI/aiohttp
AIOHTTP: HTTP request smuggling via WebSocket upgrade
04 Aug
Fix available
Severity - 6.3 (Medium)
PYSEC-2026-3547
PyPI/aiohttp
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
04 Aug
Fix available
Severity - 6.9 (Medium)
GHSA-cq5v-8q36-5273
PyPI/aiohttp
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
03 Aug
Fix available
Severity - 7.1 (High)
GHSA-mfx4-hv73-q22v
PyPI/aiohttp
AIOHTTP: HTTP request smuggling via WebSocket upgrade
03 Aug
Fix available
Severity - 6.3 (Medium)
GHSA-mq44-7p77-q5h7
PyPI/aiohttp
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
03 Aug
Fix available
Severity - 6.9 (Medium)
PYSEC-2026-1105
PyPI/aiohttp
AIOHTTP Vulnerable to Cookie Parser Warning Storm
07 Jul
Fix available
Severity - 2.7 (Low)
PYSEC-2026-1106
PyPI/aiohttp
AIOHTTP vulnerable to DoS through chunked messages
07 Jul
Fix available
Severity - 6.6 (Medium)
PYSEC-2026-1100
PyPI/aiohttp
AIOHTTP vulnerable to denial of service through large payloads
07 Jul
Fix available
Severity - 6.6 (Medium)
PYSEC-2026-1107
PyPI/aiohttp
AIOHTTP vulnerable to DoS when bypassing asserts
07 Jul
Fix available
Severity - 6.6 (Medium)
PYSEC-2026-1097
PyPI/aiohttp
AIOHTTP vulnerable to brute-force leak of internal static file path components
07 Jul
Fix available
Severity - 2.7 (Low)
PYSEC-2026-1109
PyPI/aiohttp
AIOHTTP has unicode match groups in regexes for ASCII protocol elements
07 Jul
Fix available
Severity - 2.7 (Low)
PYSEC-2026-1099
PyPI/aiohttp
AIOHTTP's unicode processing of header values could cause parsing discrepancies
07 Jul
Fix available
Severity - 2.7 (Low)
PYSEC-2026-1101
PyPI/aiohttp
AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
07 Jul
Fix available
Severity - 7.5 (High)
PYSEC-2026-1104
PyPI/aiohttp
AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
07 Jul
Fix available
Severity - 1.7 (Low)
PYSEC-2026-1103
PyPI/aiohttp
aiohttp allows request smuggling due to incorrect parsing of chunk extensions
07 Jul
Fix available
Severity - 6.3 (Medium)
Load more...
PyPI - OSV