Live data from GitHub and PyPI, updated daily.
Data last fetched: 2026-05-15
10 active CVEs reported via OSV.dev
aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method
AIOHTTP has CRLF injection through multipart part content type header construction
AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS
aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parser
AIOHTTP vulnerable to brute-force leak of internal static ο¬le path components
aiohttp is vulnerable to directory traversal
aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests
AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass
AIOHTTP's unicode processing of header values could cause parsing discrepancies
AIOHTTP vulnerable to denial of service through large payloads
Other Web Framework projects in the Python ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for aiohttp β without relying on volunteer maintainers.
Talk to an Expert β