Security: aio-libs/aiohttp
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
CRLF injection in multipart part content type header constructionGHSA-2vrm-gr82-f7m5 published
Mar 31, 2026 by DreamsorcererLow -
Denial of Service (DoS) via Unbounded DNS Cache in TCPConnectorGHSA-hcc4-c3v8-rx92 published
Mar 31, 2026 by DreamsorcererLow -
Uncapped memory usage possible via headers/trailersGHSA-w2fm-2cpv-w7v5 published
Mar 31, 2026 by DreamsorcererModerate -
Deserialization of Untrusted Data in aiohttpGHSA-jg22-mg44-37j8 published
Jun 2, 2026 by DreamsorcererModerate -
DoS through chunked messagesGHSA-g84x-mcqj-x9qq published
Jan 5, 2026 by DreamsorcererModerate -
Cookie Parser Warning StormGHSA-fh55-r93g-j68g published
Jan 5, 2026 by DreamsorcererLow -
Denial of service through large payloadsGHSA-6jhg-hg63-jvvf published
Jan 5, 2026 by DreamsorcererHigh -
DoS when bypassing assertsGHSA-jj3x-wxrx-4x23 published
Jan 5, 2026 by DreamsorcererHigh -
Brute-force leak of internal static file path componentsGHSA-54jq-c3m8-4m76 published
Jan 5, 2026 by DreamsorcererLow -
Unicode match groups in regexes for ASCII protocol elementsGHSA-mqqc-3gqh-h2x8 published
Jan 5, 2026 by DreamsorcererLow