HIGH7.5CVE-2026-54275aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections from 0
HIGH7.2CVE-2023-49081aiohttp's ClientSession is vulnerable to CRLF injection via version from 0, < 3.7.4-1+deb11u1
MEDIUM6.5CVE-2024-23829aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators from 0, < 3.7.4-1+deb11u1
MEDIUM5.9aiohttp is vulnerable to directory traversal
from 0, < 3.7.4-1+deb11u1
MEDIUM5.3aiohttp's ClientSession is vulnerable to CRLF injection via method
from 0, < 3.7.4-1+deb11u1
MEDIUM5.3python-aiohttp - security update
from 0, < 3.7.4-1+deb11u1
MEDIUM5.3python-aiohttp - security update
from 0, < 3.7.4-1+deb11u1
MEDIUM5.3python-aiohttp - security update
from 0, < 3.8.4-1+deb12u1
MEDIUM5.3aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parser
from 0
LOW3.4Aiohttp has inconsistent interpretation of `Content-Length` vs. `Transfer-Encoding` differing in C and Python fallbacks
from 0, < 3.7.4-1+deb11u1