Live data from GitHub and PyPI, updated daily.
Data last fetched: 2026-06-29
10 active CVEs reported via OSV.dev
aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method
aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence
AIOHTTP has CRLF injection through multipart part content type header construction
AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS
aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parser
aiohttp: HTTP/1 Pipelined Requests Queue Without Limit
aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
AIOHTTP vulnerable to brute-force leak of internal static file path components
aiohttp is vulnerable to directory traversal
aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests
Other Web Framework projects in the Python ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for aiohttp — without relying on volunteer maintainers.