py-aiohttp
Supports both client and server side of HTTP protocol. Supports both client and server Web-Sockets out-of-the-box and avoids Callbacks. Provides Web-server with middlewares and plugable routing.
Security Advisories for py-aiohttp in spack
Repackage
Low
11 months ago
AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
pypi
aiohttp
Repackage
Moderate
over 1 year ago
aiohttp allows request smuggling due to incorrect parsing of chunk extensions
pypi
aiohttp
Repackage
Moderate
over 1 year ago
aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method
pypi
aiohttp
Repackage
Moderate
almost 2 years ago
In aiohttp, compressed files as symlinks are not protected from path traversal
pypi
aiohttp
Repackage
High
about 2 years ago
aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests
pypi
aiohttp
Repackage
Moderate
about 2 years ago
aiohttp Cross-site Scripting vulnerability on index pages for static file handling
pypi
aiohttp
Repackage
Repackage
Moderate
over 2 years ago
aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators
pypi
aiohttp
Repackage
Moderate
over 2 years ago
aiohttp's ClientSession is vulnerable to CRLF injection via version
pypi
aiohttp
Repackage
Moderate
over 2 years ago
aiohttp's ClientSession is vulnerable to CRLF injection via method
pypi
aiohttp
Repackage
Moderate
over 2 years ago
aiohttp has vulnerable dependency that is vulnerable to request smuggling
pypi
aiohttp
Repackage
Moderate
over 2 years ago
AIOHTTP has problems in HTTP parser (the python one, not llhttp)
pypi
aiohttp
Repackage
Low
over 2 years ago
Aiohttp has inconsistent interpretation of `Content-Length` vs. `Transfer-Encoding` differing in C and Python fallbacks
pypi
aiohttp
Repackage
Moderate
almost 3 years ago
aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parser
pypi
aiohttp
Repackage
Low
over 5 years ago
`aiohttp` Open Redirect vulnerability (`normalize_path_middleware` middleware)
pypi
aiohttp