© 2025-2026 PySpect
First version without a known vulnerability: 4.0.0a0
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
Fixed in: 3.14.3
AIOHTTP: HTTP request smuggling via WebSocket upgrade
Fixed in: 3.14.2
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
Fixed in: 3.14.2
aiohttp: Incomplete websocket frame payloads bypass memory limits
Fixed in: 3.14.1
aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
Fixed in: 3.14.1
aiohttp: Payload Response Resources Are Not Closed After Mid-Body Disconnect
Fixed in: 3.14.1
aiohttp: HTTP/1 Pipelined Requests Queue Without Limit
Fixed in: 3.14.1
aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup
Fixed in: 3.14.1
aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines
Fixed in: 3.14.1
aiohttp: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges
Fixed in: 3.14.1
aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence
Fixed in: 3.14.1
aiohttp: CRLF injection in multipart headers
Fixed in: 3.14.0
AIOHTTP is vulnerable to cross-origin redirect with per-request cookies
Fixed in: 3.14.0
AIOHTTP is Vulnerable to Deserialization of Untrusted Data
Fixed in: 3.14.0
AIOHTTP accepts duplicate Host headers
Fixed in: 3.13.4
AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass
Fixed in: 3.13.4
AIOHTTP has HTTP response splitting via \r in reason phrase
Fixed in: 3.13.4
AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect
Fixed in: 3.13.4
AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS
Fixed in: 3.13.4
AIOHTTP has a Multipart Header Size Bypass
Fixed in: 3.13.4
AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows
Fixed in: 3.13.4
AIOHTTP has CRLF injection through multipart part content type header construction
Fixed in: 3.13.4
AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector
Fixed in: 3.13.4
aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage
Fixed in: 3.13.4
AIOHTTP Vulnerable to Cookie Parser Warning Storm
Fixed in: 3.13.3
AIOHTTP vulnerable to DoS through chunked messages
Fixed in: 3.13.3
AIOHTTP vulnerable to denial of service through large payloads
Fixed in: 3.13.3
AIOHTTP vulnerable to DoS when bypassing asserts
Fixed in: 3.13.3
AIOHTTP vulnerable to brute-force leak of internal static file path components
Fixed in: 3.13.3
AIOHTTP has unicode match groups in regexes for ASCII protocol elements
Fixed in: 3.13.3
AIOHTTP's unicode processing of header values could cause parsing discrepancies
Fixed in: 3.13.3
AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
Fixed in: 3.13.3
AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
Fixed in: 3.12.14
aiohttp allows request smuggling due to incorrect parsing of chunk extensions
Fixed in: 3.10.11
aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method
Fixed in: 3.10.11
In aiohttp, compressed files as symlinks are not protected from path traversal
Fixed in: 3.10.2
aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests
Fixed in: 3.9.4
aiohttp Cross-site Scripting vulnerability on index pages for static file handling
Fixed in: 3.9.4
aiohttp is vulnerable to directory traversal
Fixed in: 3.9.2, 1c335944d6a8b1298baf179b7c0b3069f10c514b
aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators
Fixed in: 3.9.2, 33ccdfb0a12690af5bb49bda2319ec0907fa7827
aiohttp's ClientSession is vulnerable to CRLF injection via version
Fixed in: 3.9.0, 1e86b777e61cf4eefc7d92fa57fa19dcc676013b
aiohttp's ClientSession is vulnerable to CRLF injection via method
Fixed in: 3.9.0, e4ae01c2077d2cfa116aa82e4ff6866857f7c466
aiohttp has vulnerable dependency that is vulnerable to request smuggling
Fixed in: 3.8.6
AIOHTTP has problems in HTTP parser (the python one, not llhttp)
Fixed in: 3.8.6, d5c12ba890557a575c313bb3017910d7616fce3d
Aiohttp has inconsistent interpretation of `Content-Length` vs. `Transfer-Encoding` differing in C and Python fallbacks
Fixed in: 3.8.0, f016f0680e4ace6742b03a70cb0382ce86abe371
aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parser
Fixed in: 3.8.5
`aiohttp` Open Redirect vulnerability (`normalize_path_middleware` middleware)
Fixed in: 3.7.4, 2545222a3853e31ace15d87ae0e2effb7da0c96b