Aiohttp
This hub aggregates every CVE we track for Aiohttp, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
36
CVEs tracked
1
Critical
14
High
0
In CISA KEV
Severity distribution
MEDIUM19HIGH14LOW2CRITICAL1
Monthly trend
0
2
0
0
2
0
0
0
0
0
0
0
1
0
0
0
0
0
8
0
0
10
0
2
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Aiohttp.
- CVE-2026-47265AIOHTTP vulnerable to cross-origin redirect with per-request cookies7.5
- CVE-2026-34993AIOHTTP Vulnerable to Deserialization of Untrusted Data6.4
- CVE-2026-34525AIOHTTP: Duplicate Host header accepted5.3
- CVE-2026-34520AIOHTTP: C parser (llhttp) accepts null bytes and control characters in response header values - header injection / security bypass9.1
- CVE-2026-34519AIOHTTP: HTTP response splitting via \r in reason phrase5.3
- CVE-2026-34518AIOHTTP: Cookie and Proxy-Authorization headers leaked on cross-origin redirect5.3
- CVE-2026-34517AIOHTTP: Late size enforcement for non-file multipart fields causes memory DoS5.3
- CVE-2026-34516AIOHTTP: Multipart Header Size Bypass7.5
- CVE-2026-34515AIOHTTP: UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows7.5
- CVE-2026-34514AIOHTTP: CRLF injection in multipart part content type header construction5.3
- CVE-2026-22815AIOHTTP: Uncapped memory usage possible through aiohttp allowing unlimited trailer headers7.5
- CVE-2026-34513AIOHTTP: Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector7.5
- CVE-2025-69230AIOHTTP Vulnerable to Cookie Parser Warning Storm5.3
- CVE-2025-69229AIOHTTP vulnerable to DoS through chunked messages5.3
- CVE-2025-69228AIOHTTP vulnerable to denial of service through large payloads7.5
Product normalization is registry-driven with AI assist and human review. How it works