llhttp 8.1.1 is vulnerable to two request smuggling vulnerabilities. Details have not been disclosed yet, so refer to llhttp for future information. The issue is resolved by using llhttp 9+ (which is included in aiohttp 3.8.6+).
{
"cwe_ids": [
"CWE-444"
],
"github_reviewed": true,
"severity": "MODERATE",
"github_reviewed_at": "2023-11-27T23:15:38Z",
"nvd_published_at": null
}