Aio Libs maintains a small set of asynchronous I/O libraries for Python, including aiohttp_session and aiosmtpd, that enable non-blocking network communication and email handling in event-driven applications. The vendor's disclosures reflect the input-validation and protocol-handling surface inherent to network libraries; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aio Libs over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000814MEDIUM aio-libs aiohttp-session version 2.6.0 and earlier contains a Other/Unknown vulnerability in EncryptedCookieStorage and NaClCookieStorage that can result in Non-expiring sessions / | Dec 20, 2018 | 6.5 | 21 | NO | NO |
CVE-2018-1000519MEDIUM aio-libs aiohttp-session contains a Session Fixation vulnerability in load_session function for RedisStorage (see: https://github.com/aio-libs/aiohttp-session/blob/master/aiohttp_s | Jun 26, 2018 | 6.5 | 20 | NO | NO |
CVE-2024-27305MEDIUM aiosmtpd is a reimplementation of the Python stdlib smtpd.py based on asyncio. aiosmtpd is vulnerable to inbound SMTP smuggling. SMTP smuggling is a novel vulnerability based on no | Mar 12, 2024 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aio Libs.
Media articles that mention a CVE ID that affects a product developed by Aio Libs — matched by CVE ID, not by vendor name.