Security: aio-libs/aiohttp
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
ClientSession is vulnerable to CRLF injection via methodGHSA-qvrw-v9rv-5rjx published
Nov 26, 2023 by DreamsorcererLow -
ClientSession is vulnerable to CRLF injection via versionGHSA-q3qx-c6g2-7pw2 published
Nov 26, 2023 by DreamsorcererLow -
Problems in HTTP parser (the python one, not llhttp)GHSA-gfw2-4jvh-wgfg published
Nov 14, 2023 by DreamsorcererModerate -
llhttp 8.1.1 vulnerable to request smugglingGHSA-pjjw-qhg8-p2p9 published
Nov 25, 2023 by DreamsorcererModerate -
aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parserGHSA-45c4-8wx5-qw6w published
Jul 19, 2023 by webknjazModerate -
Inconsistent interpretation of `Content-Length` vs. `Transfer-Encoding` differing in C and Python fallbacksGHSA-xx9p-xxvh-7g8j published
Nov 14, 2023 by DreamsorcererLow -
Open redirect vulnerability in `aiohttp` (`normalize_path_middleware` middleware)GHSA-v6wp-4m6f-gcjg published
Feb 25, 2021 by webknjazLow