Vulnerability index

Browse CVEs

39 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Aiohttp HIGH 7.5
CVE-2026-54275

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS SNI check can be bypassed wh…

Fix: 3.14.1+
Fix from $1,950 2026-06-22
Aiohttp HIGH 7.5
CVE-2026-54277

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypass the max_line_size check in …

Fix: 3.14.1+
Fix from $1,950 2026-06-22
Aiohttp HIGH 7.5
CVE-2026-54278

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed reque…

Fix: 3.14.1+
Fix from $1,950 2026-06-22
Aiohttp HIGH 7.5
CVE-2026-54279

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save…

Fix: 3.14.1+
Fix from $1,950 2026-06-22
Aiohttp HIGH 7.5
CVE-2026-54280

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a cl…

Fix: 3.14.1+
Fix from $1,950 2026-06-22
Aiohttp MEDIUM 6.1
CVE-2026-54276

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication resp…

Fix: 3.14.1+
Fix from $1,600 2026-06-22
Aiohttp HIGH 7.5
CVE-2026-54273

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on the number of pipelined requ…

Fix: 3.14.1+
Fix from $1,950 2026-06-22
Aiohttp HIGH 7.5
CVE-2026-54274

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket fram…

Fix: 3.14.1+
Fix from $1,950 2026-06-22
Aiohttp HIGH 7.5
CVE-2026-50269

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled input included into multipart/pa…

Fix: 3.14.0+
Fix from $1,950 2026-06-22
Aiohttp HIGH 7.5
CVE-2026-47265

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the `cookies` parameter on …

Fix: 3.14.0+
Fix from $1,950 2026-06-02
Aiohttp HIGH 7.3
CVE-2026-34993

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted in…

Fix: 3.14.0+
Fix from $1,950 2026-06-02
Aiohttp CRITICAL 9.1
CVE-2026-34520

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs)…

Fix: 3.13.4+
Fix from $2,300 2026-04-01
Aiohttp MEDIUM 5.3
CVE-2026-34518

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, when following redirects to a different orig…

Fix: 3.13.4+
Fix from $1,600 2026-04-01
Aiohttp MEDIUM 5.3
CVE-2026-34519

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the reason paramete…

Fix: 3.13.4+
Fix from $1,600 2026-04-01
Aiohttp MEDIUM 5.3
CVE-2026-34525

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohtt…

Fix: 3.13.4+
Fix from $1,600 2026-04-01
Aiohttp HIGH 7.5
CVE-2026-34513

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in exces…

Fix: 3.13.4+
Fix from $1,950 2026-04-01
Aiohttp HIGH 7.5
CVE-2026-34515

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the static resource handler may e…

Fix: 3.13.4+
Fix from $1,950 2026-04-01
Aiohttp HIGH 7.5
CVE-2026-34516

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, a response with an excessive number of multi…

Fix: 3.13.4+
Fix from $1,950 2026-04-01
Aiohttp MEDIUM 5.3
CVE-2026-34514

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the content_type pa…

Fix: 3.13.4+
Fix from $1,600 2026-04-01
Aiohttp MEDIUM 5.3
CVE-2026-34517

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, for some multipart form fields, aiohttp read…

Fix: 3.13.4+
Fix from $1,600 2026-04-01
Aiohttp HIGH 7.5
CVE-2026-22815

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer …

Fix: 3.13.4+
Fix from $1,950 2026-04-01
Aiohttp HIGH 7.5
CVE-2025-69227

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow for an infinite loop to occur when as…

Fix: 3.13.3+
Fix from $1,950 2026-01-06
Aiohttp HIGH 7.5
CVE-2025-69228

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way…

Fix: 3.13.3+
Fix from $1,950 2026-01-06
Aiohttp MEDIUM 5.3
CVE-2025-69229

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling of chunked messages can result…

Fix: 3.13.3+
Fix from $1,600 2026-01-06
Aiohttp MEDIUM 5.3
CVE-2025-69230

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can le…

Fix: 3.13.3+
Fix from $1,600 2026-01-06
Aiohttp MEDIUM 5.3
CVE-2025-69225

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII…

Fix: 3.13.3+
Fix from $1,600 2026-01-06
Aiohttp MEDIUM 6.5
CVE-2025-69224

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below of the Python HTTP parser may allow a reque…

Fix: 3.13.3+
Fix from $1,600 2026-01-05
Aiohttp MEDIUM 5.3
CVE-2025-69226

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existen…

Fix: 3.13.3+
Fix from $1,600 2026-01-05
Aiohttp HIGH 7.5
CVE-2025-69223

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a Do…

Fix: 3.13.3+
Fix from $1,950 2026-01-05
Aiohttp HIGH 7.5
CVE-2025-53643

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a reques…

Fix: 3.12.14+
Fix from $1,950 2025-07-14