Security Advisories for aiohttp in pypi
High
5 days ago
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
pypi
aiohttp
Moderate
5 days ago
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
pypi
aiohttp
Moderate
about 2 months ago
aiohttp: Incomplete websocket frame payloads bypass memory limits
pypi
aiohttp
Low
about 2 months ago
aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
pypi
aiohttp
Low
about 2 months ago
aiohttp: Payload Response Resources Are Not Closed After Mid-Body Disconnect
pypi
aiohttp
Moderate
about 2 months ago
aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup
pypi
aiohttp
Moderate
about 2 months ago
aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines
pypi
aiohttp
Moderate
about 2 months ago
aiohttp: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges
pypi
aiohttp
Low
about 2 months ago
aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence
pypi
aiohttp
Moderate
2 months ago
AIOHTTP is vulnerable to cross-origin redirect with per-request cookies
pypi
aiohttp
Low
4 months ago
AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect
pypi
aiohttp
Low
4 months ago
AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS
pypi
aiohttp
Moderate
4 months ago
AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows
pypi
aiohttp
Low
4 months ago
AIOHTTP has CRLF injection through multipart part content type header construction
pypi
aiohttp
Low
4 months ago
AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector
pypi
aiohttp
Moderate
4 months ago
aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage
pypi
aiohttp
Low
7 months ago
AIOHTTP vulnerable to brute-force leak of internal static file path components
pypi
aiohttp
Low
7 months ago
AIOHTTP has unicode match groups in regexes for ASCII protocol elements
pypi
aiohttp
Low
7 months ago
AIOHTTP's unicode processing of header values could cause parsing discrepancies
pypi
aiohttp
High
7 months ago
AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
pypi
aiohttp
Low
about 1 year ago
AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
pypi
aiohttp
Moderate
over 1 year ago
aiohttp allows request smuggling due to incorrect parsing of chunk extensions
pypi
aiohttp
Moderate
over 1 year ago
aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method
pypi
aiohttp
Moderate
almost 2 years ago
In aiohttp, compressed files as symlinks are not protected from path traversal
pypi
aiohttp
High
over 2 years ago
aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests
pypi
aiohttp
Moderate
over 2 years ago
aiohttp Cross-site Scripting vulnerability on index pages for static file handling
pypi
aiohttp
Moderate
over 2 years ago
aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators
pypi
aiohttp
Moderate
over 2 years ago
aiohttp's ClientSession is vulnerable to CRLF injection via version
pypi
aiohttp
Moderate
over 2 years ago
aiohttp's ClientSession is vulnerable to CRLF injection via method
pypi
aiohttp
Moderate
over 2 years ago
aiohttp has vulnerable dependency that is vulnerable to request smuggling
pypi
aiohttp
Moderate
over 2 years ago
AIOHTTP has problems in HTTP parser (the python one, not llhttp)
pypi
aiohttp
Low
over 2 years ago
Aiohttp has inconsistent interpretation of `Content-Length` vs. `Transfer-Encoding` differing in C and Python fallbacks
pypi
aiohttp
Moderate
about 3 years ago
aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parser
pypi
aiohttp
Low
over 5 years ago
`aiohttp` Open Redirect vulnerability (`normalize_path_middleware` middleware)
pypi
aiohttp