Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-37276

21
FAUCET Score

CVE-2023-37276 is a high-severity HTTP request smuggling vulnerability affecting aiohttp versions 3.8.4 and earlier when used as an HTTP server. A crafted HTTP request can cause the server to misinterpret header values, leading to request smuggling. The vulnerability has a CVSS score of 7.5, indicating a network-based attack with low complexity and a high impact on integrity. While there is no evidence of active exploitation, public exploit code, or significant community discussion, users are advised to upgrade to aiohttp 3.8.5 or reinstall with AIOHTTP_NO_EXTENSIONS=1 to mitigate the risk.

Impacted Technologies

VendorProductVersion(s)CPE
<= 3.8.4CPE matchmatch criteria
cpe:2.3:a:aiohttp:aiohttp:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.34%
Probability of exploitation in next 30 days
EPSS Percentile
68.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0134 is in the 48th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: aiohttpFixed in: 3.8.5
redhatpatch availablevia redhat_api
Product: Red Hat Satellite 6.15 for RHEL 8Fixed in: python-aiohttp-0:3.9.2-1.el8pc
View patch
redhatpatch availablevia redhat_api
Product: RHUI 4 for RHEL 8Fixed in: python-aiohttp-0:3.9.2-1.el8ui
View patch
redhatno patchvia redhat_api
Product: Red Hat OpenShift Data Science (RHODS)Fixed in: python-aiohttp
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: python-aiohttp
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 17.1Fixed in: python-aiohttp
redhatend of lifevia redhat_api
Product: Red Hat Ansible Automation Platform 1.2Fixed in: python-aiohttp

Vendor Advisories (2)

pipGHSA-45c4-8wx5-qw6wmedium

aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parser

Jul 20, 2023
redhatCVE-2023-37276Moderate

python-aiohttp: HTTP request smuggling via llhttp HTTP request parser

Jul 19, 2023

References

github.com / aio-libs/aiohttp/blob/v3.8.4/.gitmodules
Product
github.com / aio-libs/aiohttp/commit/9337fb3f2ab2b5f38d7e98a194bde6f7e3d16c40
Patch
github.com / aio-libs/aiohttp/security/advisories/GHSA-45c4-8wx5-qw6w
ExploitMitigationVendor Advisory
hackerone.com / reports/2001873
ExploitThird Party Advisory