CVE Tools

Aiohttp

33 CVEs tracked since 2023. Since Nov 2023, none of them reached CISA KEV.

Aiohttp CVEs per month

Nov 2023 to Jun 2026. Point at a month, or focus the strip and use the arrow keys.
Aiohttp CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2023-1140
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-0180
2026-02null or fewer
2026-03null or fewer
2026-04100
2026-05null or fewer
2026-06110

Products

The products that kept showing up in Aiohttp's monthly top three, with their CVEs summed over those months.

  1. Aiohttp334 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Aiohttp.

  1. CVE-2026-54273AIOHTTP: HTTP/1 Pipelined Requests Queue Without Limit7.5
  2. CVE-2026-54280AIOHTTP: Payload Response Resources Are Not Closed After Mid-Body Disconnect7.5
  3. CVE-2026-54278AIOHTTP: Unread Compressed Request Bodies Bypass client_max_size During Cleanup7.5
  4. CVE-2026-54277AIOHTTP: C HTTP Parser Bypasses max_line_size for Fragmented Lines7.5
  5. CVE-2026-54276AIOHTTP: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges6.1
  6. CVE-2026-54275AIOHTTP: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections7.5
  7. CVE-2026-54274AIOHTTP: Incomplete websocket frame payloads bypass memory limits7.5
  8. CVE-2026-54279AIOHTTP: Host-Only Cookies Become Domain Cookies After CookieJar Persistence7.5
  9. CVE-2026-50269AIOHTTP: CRLF injection in multipart headers7.5
  10. CVE-2026-47265AIOHTTP vulnerable to cross-origin redirect with per-request cookies7.5
  11. CVE-2026-34993AIOHTTP Vulnerable to Deserialization of Untrusted Data6.4
  12. CVE-2026-34525AIOHTTP: Duplicate Host header accepted5.3
  13. CVE-2026-34520AIOHTTP: C parser (llhttp) accepts null bytes and control characters in response header values - header injection / security bypass9.1
  14. CVE-2026-34519AIOHTTP: HTTP response splitting via \r in reason phrase5.3
  15. CVE-2026-34518AIOHTTP: Cookie and Proxy-Authorization headers leaked on cross-origin redirect5.3

The record

Peak rank
#101 in Apr 2026
Busiest month shown
Jun 2026, 11 CVEs
Months with a KEV entry
0 since Nov 2023
Monthly snapshots
4 since 2023
Aiohttp's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store