{"schema_version":1,"title":"aiohttp (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 47 vulnerabilities in aiohttp (PyPI): 0 in the last 7 days and 15 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-69244, was published on 3 August 2026.","url":"https://junglewise.ai/threats/technologies/aiohttp","json_url":"https://junglewise.ai/threats/technologies/aiohttp.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/aiohttp","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":47,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":15,"last_365_days":38},"latest":[{"cve":"CVE-2026-69244","cvss":4,"epss":0.0053,"slug":"cve-2026-69244-aiohttp-out-of-bounds-heap-read-in-c-http-response-parser","title":"AIOHTTP out-of-bounds heap read in C HTTP response parser","severity":"high","exploited":false,"published_at":"2026-08-03T20:51:13+00:00","url":"https://junglewise.ai/threats/cve-2026-69244-aiohttp-out-of-bounds-heap-read-in-c-http-response-parser"},{"cve":"CVE-2026-69243","cvss":4,"epss":0.0044,"slug":"cve-2026-69243-aiohttp-request-smuggling-in-websocket-upgrade","title":"AIOHTTP request smuggling in WebSocket upgrade","severity":"medium","exploited":false,"published_at":"2026-08-03T20:46:10+00:00","url":"https://junglewise.ai/threats/cve-2026-69243-aiohttp-request-smuggling-in-websocket-upgrade"},{"cve":"CVE-2026-59881","cvss":4,"epss":0.0052,"slug":"cve-2026-59881-aio-libs-aiohttp-resource-exhaustion-in-websocket-client","title":"aio-libs aiohttp resource exhaustion in WebSocket client decompression","severity":"medium","exploited":false,"published_at":"2026-07-30T19:18:33.597+00:00","url":"https://junglewise.ai/threats/cve-2026-59881-aio-libs-aiohttp-resource-exhaustion-in-websocket-client"},{"cve":"CVE-2025-69229","cvss":4,"epss":0.004,"slug":"cve-2025-69229-aiohttp-vulnerable-to-dos-through-chunked-messages","title":"PYSEC-2026-1106 - AIOHTTP vulnerable to DoS through chunked messages","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:16.385072+00:00","url":"https://junglewise.ai/threats/cve-2025-69229-aiohttp-vulnerable-to-dos-through-chunked-messages"},{"cve":"CVE-2025-69228","cvss":4,"epss":0.004,"slug":"cve-2025-69228-aiohttp-vulnerable-to-denial-of-service-through-large-payloads","title":"PYSEC-2026-1100 - AIOHTTP vulnerable to denial of service through large payloads","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:16.15284+00:00","url":"https://junglewise.ai/threats/cve-2025-69228-aiohttp-vulnerable-to-denial-of-service-through-large-payloads"},{"cve":"CVE-2025-69227","cvss":4,"epss":0.0039,"slug":"cve-2025-69227-aiohttp-vulnerable-to-dos-when-bypassing-asserts","title":"PYSEC-2026-1107 - AIOHTTP vulnerable to DoS when bypassing asserts","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:15.809963+00:00","url":"https://junglewise.ai/threats/cve-2025-69227-aiohttp-vulnerable-to-dos-when-bypassing-asserts"},{"cve":"CVE-2025-69226","cvss":4,"epss":0.0036,"slug":"cve-2025-69226-aiohttp-vulnerable-to-brute-force-leak-of-internal-static-le-path","title":"PYSEC-2026-1097 - AIOHTTP vulnerable to brute-force leak of internal static ﬁle path components","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:15.61125+00:00","url":"https://junglewise.ai/threats/cve-2025-69226-aiohttp-vulnerable-to-brute-force-leak-of-internal-static-le-path"},{"cve":"CVE-2025-69225","cvss":4,"epss":0.0028,"slug":"cve-2025-69225-aiohttp-has-unicode-match-groups-in-regexes-for-ascii-protocol","title":"PYSEC-2026-1109 - AIOHTTP has unicode match groups in regexes for ASCII protocol elements","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:15.425479+00:00","url":"https://junglewise.ai/threats/cve-2025-69225-aiohttp-has-unicode-match-groups-in-regexes-for-ascii-protocol"},{"cve":"CVE-2025-69224","cvss":4,"epss":0.0024,"slug":"cve-2025-69224-aiohttp-s-unicode-processing-of-header-values-could-cause-parsing","title":"PYSEC-2026-1099 - AIOHTTP's unicode processing of header values could cause parsing discrepancies","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:15.238774+00:00","url":"https://junglewise.ai/threats/cve-2025-69224-aiohttp-s-unicode-processing-of-header-values-could-cause-parsing"},{"cve":"CVE-2025-53643","cvss":4,"epss":0.0031,"slug":"cve-2025-53643-aiohttp-is-vulnerable-to-http-request-response-smuggling-through","title":"PYSEC-2026-1104 - AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections","severity":"medium","exploited":false,"published_at":"2026-07-07T16:02:58.01777+00:00","url":"https://junglewise.ai/threats/cve-2025-53643-aiohttp-is-vulnerable-to-http-request-response-smuggling-through"},{"cve":"CVE-2024-52304","cvss":4,"epss":0.0056,"slug":"cve-2024-52304-aiohttp-allows-request-smuggling-due-to-incorrect-parsing-of","title":"PYSEC-2026-1103 - aiohttp allows request smuggling due to incorrect parsing of chunk extensions","severity":"medium","exploited":false,"published_at":"2026-07-07T14:34:45.226773+00:00","url":"https://junglewise.ai/threats/cve-2024-52304-aiohttp-allows-request-smuggling-due-to-incorrect-parsing-of"},{"cve":"CVE-2024-52303","cvss":3.1,"epss":0.0059,"slug":"cve-2024-52303-aiohttp-memory-leak-in-middleware-with-non-allowed-http-methods","title":"PYSEC-2026-1096 - aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:45.010533+00:00","url":"https://junglewise.ai/threats/cve-2024-52303-aiohttp-memory-leak-in-middleware-with-non-allowed-http-methods"},{"cve":"CVE-2024-42367","cvss":3.1,"epss":0.0065,"slug":"cve-2024-42367-in-aiohttp-compressed-files-as-symlinks-are-not-protected-from","title":"PYSEC-2026-1108 - In aiohttp, compressed files as symlinks are not protected from path traversal","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:38.838715+00:00","url":"https://junglewise.ai/threats/cve-2024-42367-in-aiohttp-compressed-files-as-symlinks-are-not-protected-from"},{"cve":"CVE-2024-30251","cvss":3.1,"epss":0.0109,"slug":"cve-2024-30251-aiohttp-vulnerable-to-denial-of-service-when-trying-to-parse","title":"PYSEC-2026-1098 - aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:40.794194+00:00","url":"https://junglewise.ai/threats/cve-2024-30251-aiohttp-vulnerable-to-denial-of-service-when-trying-to-parse"},{"cve":"CVE-2024-27306","cvss":3.1,"epss":0.0067,"slug":"cve-2024-27306-aiohttp-cross-site-scripting-vulnerability-on-index-pages-for","title":"PYSEC-2026-1102 - aiohttp Cross-site Scripting vulnerability on index pages for static file handling","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:39.766336+00:00","url":"https://junglewise.ai/threats/cve-2024-27306-aiohttp-cross-site-scripting-vulnerability-on-index-pages-for"},{"cve":"CVE-2026-54280","cvss":4,"epss":0.0046,"slug":"cve-2026-54280-aiohttp-improper-resource-shutdown-in-payload-handling","title":"AIOHTTP improper resource shutdown in payload handling","severity":"medium","exploited":false,"published_at":"2026-06-22T18:16:46.67+00:00","url":"https://junglewise.ai/threats/cve-2026-54280-aiohttp-improper-resource-shutdown-in-payload-handling"},{"cve":"CVE-2026-54279","cvss":4,"epss":0.0049,"slug":"cve-2026-54279-aio-libs-aiohttp-host-only-cookie-scope-loss-in-cookiejar","title":"aio-libs aiohttp host-only cookie scope loss in CookieJar","severity":"medium","exploited":false,"published_at":"2026-06-22T18:16:46.527+00:00","url":"https://junglewise.ai/threats/cve-2026-54279-aio-libs-aiohttp-host-only-cookie-scope-loss-in-cookiejar"},{"cve":"CVE-2026-54278","cvss":4,"epss":0.0049,"slug":"cve-2026-54278-aio-libs-aiohttp-denial-of-service-via-compressed-request-body","title":"aio-libs aiohttp Denial of Service via compressed request body decompression","severity":"medium","exploited":false,"published_at":"2026-06-22T18:16:46.393+00:00","url":"https://junglewise.ai/threats/cve-2026-54278-aio-libs-aiohttp-denial-of-service-via-compressed-request-body"},{"cve":"CVE-2026-54277","cvss":4,"epss":0.0056,"slug":"cve-2026-54277-aio-libs-aiohttp-denial-of-service-via-max-line-size-bypass-in-c","title":"aio-libs aiohttp denial of service via max_line_size bypass in C parser","severity":"medium","exploited":false,"published_at":"2026-06-22T18:16:46.263+00:00","url":"https://junglewise.ai/threats/cve-2026-54277-aio-libs-aiohttp-denial-of-service-via-max-line-size-bypass-in-c"},{"cve":"CVE-2026-54276","cvss":4,"epss":0.0031,"slug":"cve-2026-54276-aiohttp-information-exposure-in-digestauthmiddleware-cross-origin","title":"AIOHTTP information exposure in DigestAuthMiddleware cross-origin redirects","severity":"medium","exploited":false,"published_at":"2026-06-22T18:16:46.133+00:00","url":"https://junglewise.ai/threats/cve-2026-54276-aiohttp-information-exposure-in-digestauthmiddleware-cross-origin"},{"cve":"CVE-2026-54275","cvss":4,"epss":0.0047,"slug":"cve-2026-54275-aio-libs-aiohttp-tls-sni-check-bypass-during-connection-reuse","title":"aio-libs aiohttp TLS SNI check bypass during connection reuse","severity":"medium","exploited":false,"published_at":"2026-06-22T18:16:46.01+00:00","url":"https://junglewise.ai/threats/cve-2026-54275-aio-libs-aiohttp-tls-sni-check-bypass-during-connection-reuse"},{"cve":"CVE-2026-54274","cvss":4,"epss":0.0054,"slug":"cve-2026-54274-aio-libs-aiohttp-memory-exhaustion-in-websocket-handler","title":"aio-libs aiohttp memory exhaustion in WebSocket handler","severity":"medium","exploited":false,"published_at":"2026-06-22T18:16:45.877+00:00","url":"https://junglewise.ai/threats/cve-2026-54274-aio-libs-aiohttp-memory-exhaustion-in-websocket-handler"},{"cve":"CVE-2026-54273","cvss":4,"epss":0.0049,"slug":"cve-2026-54273-aio-libs-aiohttp-denial-of-service-via-unbounded-request","title":"aio-libs aiohttp Denial of Service via unbounded request pipelining","severity":"medium","exploited":false,"published_at":"2026-06-22T18:16:45.743+00:00","url":"https://junglewise.ai/threats/cve-2026-54273-aio-libs-aiohttp-denial-of-service-via-unbounded-request"},{"cve":"CVE-2026-50269","cvss":4,"epss":0.0053,"slug":"cve-2026-50269-aio-libs-aiohttp-crlf-injection-in-multipart-headers","title":"aio-libs aiohttp CRLF injection in multipart headers","severity":"medium","exploited":false,"published_at":"2026-06-22T18:16:42.92+00:00","url":"https://junglewise.ai/threats/cve-2026-50269-aio-libs-aiohttp-crlf-injection-in-multipart-headers"},{"cve":"CVE-2026-47265","cvss":4,"epss":0.0021,"slug":"cve-2026-47265-aiohttp-sensitive-cookie-leak-during-cross-origin-redirect","title":"AIOHTTP sensitive cookie leak during cross-origin redirect","severity":"medium","exploited":false,"published_at":"2026-06-02T20:16:37.903+00:00","url":"https://junglewise.ai/threats/cve-2026-47265-aiohttp-sensitive-cookie-leak-during-cross-origin-redirect"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":12},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"}],"technology":{"hub":true,"name":"aiohttp (PyPI)","slug":"aiohttp","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://docs.aiohttp.org/","repo_url":"https://github.com/aio-libs/aiohttp","description":"An asynchronous HTTP client/server framework for Python and asyncio.","url":"https://junglewise.ai/threats/technologies/aiohttp"},"most_severe":[{"cve":"CVE-2026-34520","cvss":9.1,"epss":0.0068,"slug":"cve-2026-34520-aio-libs-aiohttp-header-injection-in-llhttp-c-parser","title":"aio-libs aiohttp header injection in llhttp C parser","severity":"critical","exploited":false,"published_at":"2026-04-01T21:49:06+00:00","url":"https://junglewise.ai/threats/cve-2026-34520-aio-libs-aiohttp-header-injection-in-llhttp-c-parser"},{"cve":"CVE-2025-69223","cvss":7.5,"epss":0.0057,"slug":"cve-2025-69223-aio-libs-aiohttp-denial-of-service-via-zip-bomb-in-http-parser","title":"aio-libs aiohttp denial of service via zip bomb in HTTP parser","severity":"high","exploited":false,"published_at":"2026-01-05T22:15:53.017+00:00","url":"https://junglewise.ai/threats/cve-2025-69223-aio-libs-aiohttp-denial-of-service-via-zip-bomb-in-http-parser"},{"cve":"CVE-2026-69244","cvss":4,"epss":0.0053,"slug":"cve-2026-69244-aiohttp-out-of-bounds-heap-read-in-c-http-response-parser","title":"AIOHTTP out-of-bounds heap read in C HTTP response parser","severity":"high","exploited":false,"published_at":"2026-08-03T20:51:13+00:00","url":"https://junglewise.ai/threats/cve-2026-69244-aiohttp-out-of-bounds-heap-read-in-c-http-response-parser"},{"cve":"CVE-2026-34993","cvss":6.4,"epss":0.005,"slug":"cve-2026-34993-aio-libs-aiohttp-code-execution-via-deserialization-in-cookiejar","title":"aio-libs aiohttp code execution via deserialization in CookieJar.load","severity":"medium","exploited":false,"published_at":"2026-06-02T20:16:34.857+00:00","url":"https://junglewise.ai/threats/cve-2026-34993-aio-libs-aiohttp-code-execution-via-deserialization-in-cookiejar"},{"cve":"CVE-2022-33124","cvss":5.5,"epss":0.0072,"slug":"cve-2022-33124-aiohttp-denial-of-service-via-invalid-ipv6-url-withdrawn","title":"aiohttp Denial of Service via invalid IPv6 URL (Withdrawn)","severity":"medium","exploited":false,"published_at":"2022-06-24T00:00:31+00:00","url":"https://junglewise.ai/threats/cve-2022-33124-aiohttp-denial-of-service-via-invalid-ipv6-url-withdrawn"},{"cve":"CVE-2026-34518","cvss":5.3,"epss":0.0041,"slug":"cve-2026-34518-aiohttp-leaks-cookie-and-proxy-authorization-headers-on-cross","title":"AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect","severity":"medium","exploited":false,"published_at":"2026-04-01T21:47:46+00:00","url":"https://junglewise.ai/threats/cve-2026-34518-aiohttp-leaks-cookie-and-proxy-authorization-headers-on-cross"},{"cve":"CVE-2025-69230","cvss":5.3,"epss":0.0037,"slug":"cve-2025-69230-aiohttp-logging-storm-in-cookie-parsing","title":"aiohttp logging storm in cookie parsing","severity":"medium","exploited":false,"published_at":"2026-01-06T00:15:48.483+00:00","url":"https://junglewise.ai/threats/cve-2025-69230-aiohttp-logging-storm-in-cookie-parsing"},{"cve":"CVE-2026-34516","cvss":4,"epss":0.0061,"slug":"cve-2026-34516-aiohttp-has-a-multipart-header-size-bypass","title":"PYSEC-2026-2098 - AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, a response with an excessive number","severity":"medium","exploited":false,"published_at":"2026-04-01T21:16:59.723+00:00","url":"https://junglewise.ai/threats/cve-2026-34516-aiohttp-has-a-multipart-header-size-bypass"},{"cve":"CVE-2026-34513","cvss":4,"epss":0.0061,"slug":"cve-2026-34513-aiohttp-affected-by-denial-of-service-dos-via-unbounded-dns-cache","title":"PYSEC-2026-2095 - AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result","severity":"medium","exploited":false,"published_at":"2026-04-01T21:16:59.267+00:00","url":"https://junglewise.ai/threats/cve-2026-34513-aiohttp-affected-by-denial-of-service-dos-via-unbounded-dns-cache"},{"cve":"CVE-2024-52304","cvss":4,"epss":0.0056,"slug":"cve-2024-52304-aiohttp-allows-request-smuggling-due-to-incorrect-parsing-of","title":"PYSEC-2026-1103 - aiohttp allows request smuggling due to incorrect parsing of chunk extensions","severity":"medium","exploited":false,"published_at":"2026-07-07T14:34:45.226773+00:00","url":"https://junglewise.ai/threats/cve-2024-52304-aiohttp-allows-request-smuggling-due-to-incorrect-parsing-of"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}