OSS Support Hub / Web Framework

Python Web Framework Apache-2.0 Latest: v3.14.1

aiohttp

Async HTTP client/server framework for Python with support for WebSockets

Project Health at a Glance

Live data from GitHub and PyPI, updated daily.

16.5K+27
GitHub Stars
📦
v3.14.1
Latest Release · 22 days ago
🔄
37d
Avg. Release Cadence
🐛
225
Open Issues
📅
Yesterday
Last Commit
🔒
10
Active CVEs

Data last fetched: 2026-06-29

Known Vulnerabilities

10 active CVEs reported via OSV.dev

aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method

Published: 2024-11-18 Fixed in: 3.10.11

aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence

Published: 2026-06-15 Fixed in: 3.14.1

AIOHTTP has CRLF injection through multipart part content type header construction

Published: 2026-04-01 Fixed in: 3.13.4

AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS

Published: 2026-04-01 Fixed in: 3.13.4

aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parser

Published: 2023-07-20 Fixed in: 3.8.5

aiohttp: HTTP/1 Pipelined Requests Queue Without Limit

Published: 2026-06-15 Fixed in: 3.14.1

aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections

Published: 2026-06-15 Fixed in: 3.14.1

AIOHTTP vulnerable to brute-force leak of internal static file path components

Published: 2026-01-05 Fixed in: 3.13.3

aiohttp is vulnerable to directory traversal

Published: 2024-01-29 Fixed in: 3.9.2

aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests

Published: 2024-05-03 Fixed in: 3.9.4

Alternatives to aiohttp

Other Web Framework projects in the Python ecosystem worth evaluating.

Support Options for aiohttp

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for aiohttp — without relying on volunteer maintainers.