Search CVE reports


Toggle filters

1 – 10 of 14 results


CVE-2025-53643

Medium priority
Needs evaluation

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability due to not parsing trailer sections of an HTTP request....

1 affected package

python-aiohttp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-52304

Medium priority

Some fixes available 4 of 5

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.10.11, the Python parser parses newlines in chunk extensions incorrectly which can lead to request smuggling vulnerabilities under...

1 affected package

python-aiohttp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-52303

Medium priority
Not affected

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions starting with 3.10.6 and prior to 3.10.11, a memory leak can occur when a request produces a MatchInfoError. This was caused by adding an...

1 affected package

python-aiohttp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-42367

Medium priority
Ignored

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions on the 3.10 branch prior to version 3.10.2, static routes which contain files with compressed variants (`.gz` or `.br` extension) are...

1 affected package

python-aiohttp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-30251

Medium priority

Some fixes available 3 of 4

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attacker can send a specially crafted POST (multipart/form-data) request. When the aiohttp server processes it, the server...

1 affected package

python-aiohttp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Fixed Fixed Fixed Not affected
Show less packages

CVE-2024-27306

Medium priority

Some fixes available 4 of 5

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse...

1 affected package

python-aiohttp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-23829

Medium priority

Some fixes available 3 of 5

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must trigger error handling to...

1 affected package

python-aiohttp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Fixed Fixed Fixed Ignored
Show less packages

CVE-2024-23334

Medium priority

Some fixes available 4 of 8

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option...

1 affected package

python-aiohttp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Fixed Fixed Fixed Fixed
Show less packages

CVE-2023-49082

Medium priority

Some fixes available 3 of 5

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even create a new HTTP request if the...

1 affected package

python-aiohttp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Not affected Fixed Fixed Fixed
Show less packages

CVE-2023-49081

Medium priority

Some fixes available 3 of 5

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for an attacker to modify the HTTP request (e.g. to insert a new header) or create a new HTTP request if the...

1 affected package

python-aiohttp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Not affected Fixed Fixed Fixed
Show less packages