Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3545
  • PyPI/aiohttp
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response) 04 Aug
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-3546
  • PyPI/aiohttp
AIOHTTP: HTTP request smuggling via WebSocket upgrade 04 Aug
  • Fix available
  • Severity - 6.3 (Medium)
PYSEC-2026-3547
  • PyPI/aiohttp
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate 04 Aug
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-cq5v-8q36-5273
  • PyPI/aiohttp
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response) 03 Aug
  • Fix available
  • Severity - 7.1 (High)
GHSA-mfx4-hv73-q22v
  • PyPI/aiohttp
AIOHTTP: HTTP request smuggling via WebSocket upgrade 03 Aug
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-mq44-7p77-q5h7
  • PyPI/aiohttp
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate 03 Aug
  • Fix available
  • Severity - 6.9 (Medium)
PYSEC-2026-1105
  • PyPI/aiohttp
AIOHTTP Vulnerable to Cookie Parser Warning Storm 07 Jul
  • Fix available
  • Severity - 2.7 (Low)
PYSEC-2026-1106
  • PyPI/aiohttp
AIOHTTP vulnerable to DoS through chunked messages 07 Jul
  • Fix available
  • Severity - 6.6 (Medium)
PYSEC-2026-1100
  • PyPI/aiohttp
AIOHTTP vulnerable to denial of service through large payloads 07 Jul
  • Fix available
  • Severity - 6.6 (Medium)
PYSEC-2026-1107
  • PyPI/aiohttp
AIOHTTP vulnerable to DoS when bypassing asserts 07 Jul
  • Fix available
  • Severity - 6.6 (Medium)
PYSEC-2026-1097
  • PyPI/aiohttp
AIOHTTP vulnerable to brute-force leak of internal static file path components 07 Jul
  • Fix available
  • Severity - 2.7 (Low)
PYSEC-2026-1109
  • PyPI/aiohttp
AIOHTTP has unicode match groups in regexes for ASCII protocol elements 07 Jul
  • Fix available
  • Severity - 2.7 (Low)
PYSEC-2026-1099
  • PyPI/aiohttp
AIOHTTP's unicode processing of header values could cause parsing discrepancies 07 Jul
  • Fix available
  • Severity - 2.7 (Low)
PYSEC-2026-1101
  • PyPI/aiohttp
AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb 07 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-1104
  • PyPI/aiohttp
AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections 07 Jul
  • Fix available
  • Severity - 1.7 (Low)
PYSEC-2026-1103
  • PyPI/aiohttp
aiohttp allows request smuggling due to incorrect parsing of chunk extensions 07 Jul
  • Fix available
  • Severity - 6.3 (Medium)