CVE Tools

Aio-libs

33 CVEs tracked since 2023. Since Nov 2023, none of them reached CISA KEV.

Aio-libs CVEs per month

Nov 2023 to Jun 2026. Point at a month, or focus the strip and use the arrow keys.
Aio-libs CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2023-1140
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-0180
2026-02null or fewer
2026-03null or fewer
2026-04100
2026-05null or fewer
2026-06110

Products

The products that kept showing up in Aio-libs's monthly top three, with their CVEs summed over those months.

  1. Aiohttp334 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Aio-libs.

  1. CVE-2026-69244AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)—
  2. CVE-2026-69243AIOHTTP: HTTP request smuggling via WebSocket upgrade—
  3. CVE-2026-59881AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate—
  4. CVE-2026-54273AIOHTTP: HTTP/1 Pipelined Requests Queue Without Limit7.5
  5. CVE-2026-54280AIOHTTP: Payload Response Resources Are Not Closed After Mid-Body Disconnect7.5
  6. CVE-2026-54278AIOHTTP: Unread Compressed Request Bodies Bypass client_max_size During Cleanup7.5
  7. CVE-2026-54277AIOHTTP: C HTTP Parser Bypasses max_line_size for Fragmented Lines7.5
  8. CVE-2026-54276AIOHTTP: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges6.1
  9. CVE-2026-54275AIOHTTP: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections7.5
  10. CVE-2026-54274AIOHTTP: Incomplete websocket frame payloads bypass memory limits7.5
  11. CVE-2026-54279AIOHTTP: Host-Only Cookies Become Domain Cookies After CookieJar Persistence7.5
  12. CVE-2026-50269AIOHTTP: CRLF injection in multipart headers7.5
  13. CVE-2026-47265AIOHTTP vulnerable to cross-origin redirect with per-request cookies7.5
  14. CVE-2026-34993AIOHTTP Vulnerable to Deserialization of Untrusted Data6.4
  15. CVE-2026-34525AIOHTTP: Duplicate Host header accepted5.3

The record

Peak rank
#102 in Apr 2026
Busiest month shown
Jun 2026, 11 CVEs
Months with a KEV entry
0 since Nov 2023
Monthly snapshots
4 since 2023
Aio-libs's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store