Security: aio-libs/aiohttp
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Incomplete websocket frame payloads bypass memory limitsGHSA-xcgm-r5h9-7989 published
Jun 8, 2026 by DreamsorcererModerate -
TLS Server Hostname Override Is Ignored When Reusing HTTPS ConnectionsGHSA-4m7w-qmgq-4wj5 published
Jun 8, 2026 by DreamsorcererLow -
Payload Response Resources Are Not Closed After Mid-Body DisconnectGHSA-9x8q-7h8h-wcw9 published
Jun 8, 2026 by DreamsorcererLow -
HTTP/1 Pipelined Requests Queue Without LimitGHSA-4fvr-rgm6-gqmc published
Jun 8, 2026 by DreamsorcererLow -
Unread Compressed Request Bodies Bypass client_max_size During CleanupGHSA-g3cq-j2xw-wf74 published
Jun 8, 2026 by DreamsorcererModerate -
C HTTP Parser Bypasses max_line_size for Fragmented LinesGHSA-63hw-fmq6-xxg2 published
Jun 8, 2026 by DreamsorcererModerate -
DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect ChallengesGHSA-hpj7-wq8m-9hgp published
Jun 8, 2026 by DreamsorcererLow -
Host-Only Cookies Become Domain Cookies After CookieJar PersistenceGHSA-2fqr-mr3j-6wp8 published
Jun 8, 2026 by DreamsorcererLow -
CRLF injection in multipart headersGHSA-m6qw-4cw2-hm4m published
Jun 4, 2026 by DreamsorcererLow -
Cross-origin redirect with per-request cookiesGHSA-hg6j-4rv6-33pg published
Jun 2, 2026 by DreamsorcererLow