Search CVE reports


Toggle filters

1 – 10 of 22 results


CVE-2025-69230

Medium priority
Needs evaluation

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can lead to a logging storm. If the cookies attribute is accessed in an application,...

1 affected package

python-aiohttp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-69229

Medium priority
Needs evaluation

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling of chunked messages can result in excessive blocking CPU usage when receiving a large number of chunks. If an...

1 affected package

python-aiohttp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-69228

Medium priority
Needs evaluation

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way that an AIOHTTP server's memory fills up uncontrollably during processing. If an...

1 affected package

python-aiohttp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-69227

Medium priority
Needs evaluation

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow for an infinite loop to occur when assert statements are bypassed, resulting in a DoS attack when processing a POST...

1 affected package

python-aiohttp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-69225

Medium priority
Needs evaluation

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the Range header. There is no known impact, but there...

1 affected package

python-aiohttp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-69226

Medium priority
Needs evaluation

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static...

1 affected package

python-aiohttp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-69224

Medium priority
Needs evaluation

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below of the Python HTTP parser may allow a request smuggling attack with the presence of non-ASCII characters. If a pure Python...

1 affected package

python-aiohttp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-69223

Medium priority
Needs evaluation

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed...

1 affected package

python-aiohttp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-53643

Medium priority
Needs evaluation

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability due to not parsing trailer sections of an HTTP request....

1 affected package

python-aiohttp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-52304

Medium priority

Some fixes available 4 of 5

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.10.11, the Python parser parses newlines in chunk extensions incorrectly which can lead to request smuggling vulnerabilities under...

1 affected package

python-aiohttp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Fixed Fixed Fixed Fixed
Show less packages