CVEs we hold for Aio-libs
Records whose assigning authority named Aio-libs as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-69244AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)aio-libs aiohttp
CVE-2026-59881AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflateaio-libs aiohttp
CVE-2026-54280AIOHTTP: Payload Response Resources Are Not Closed After Mid-Body Disconnectaio-libs aiohttp
CVE-2026-54279AIOHTTP: Host-Only Cookies Become Domain Cookies After CookieJar Persistenceaio-libs aiohttp
CVE-2026-54278AIOHTTP: Unread Compressed Request Bodies Bypass client_max_size During Cleanupaio-libs aiohttp
CVE-2026-54276AIOHTTP: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challengesaio-libs aiohttp
CVE-2026-54275AIOHTTP: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connectionsaio-libs aiohttp
CVE-2026-34520AIOHTTP: C parser (llhttp) accepts null bytes and control characters in response header values - header injection /…aio-libs aiohttp
CVE-2026-34518AIOHTTP: Cookie and Proxy-Authorization headers leaked on cross-origin redirectaio-libs aiohttp
CVE-2026-34517AIOHTTP: Late size enforcement for non-file multipart fields causes memory DoSaio-libs aiohttp
CVE-2026-34515AIOHTTP: UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windowsaio-libs aiohttp
CVE-2026-34514AIOHTTP: CRLF injection in multipart part content type header constructionaio-libs aiohttp
CVE-2026-34513AIOHTTP: Denial of Service (DoS) via Unbounded DNS Cache in TCPConnectoraio-libs aiohttp
CVE-2026-22815AIOHTTP: Uncapped memory usage possible through aiohttp allowing unlimited trailer headersaio-libs aiohttp
CVE-2025-69226AIOHTTP allows for a brute-force leak of internal static filepath componentsaio-libs aiohttp
CVE-2025-69224AIOHTTP's Unicode processing of header values could cause parsing discrepanciesaio-libs aiohttp
CVE-2025-69223AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bombaio-libs aiohttp
CVE-2025-62611aiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL serveraio-libs aiomysql
CVE-2025-53643AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sectionsaio-libs aiohttp
CVE-2024-52304aiohttp vulnerable to request smuggling due to incorrect parsing of chunk extensionsaio-libs aiohttp
CVE-2024-52303aiohttp memory leak when middleware is enabled when requesting a resource with a non-allowed methodaio-libs aiohttp
CVE-2024-42367In aiohttp, compressed files as symlinks are not protected from path traversalaio-libs aiohttp
CVE-2024-30251Denial of service when trying to parse malformed POST requests in aiohttpaio-libs aiohttp
CVE-2024-23829aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separatorsaio-libs aiohttp
CVE-2024-23334aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversalaio-libs aiohttp
CVE-2023-47641Inconsistent interpretation of `Content-Length` vs. `Transfer-Encoding` in aiohttpaio-libs aiohttp
50 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.