Aiohttp is a widely embedded Python asynchronous HTTP client and server library that spans a broad downstream footprint despite a narrowly scoped direct product range. The vendor's vulnerability exposure concentrates in a single, heavily integrated library and recurs through protocol-parsing and resource-handling weakness classes, including HTTP request smuggling, header injection, improper input validation, and unbounded resource allocation—issues that reflect the parsing and state-management complexity inherent to HTTP protocol implementations. Given aiohttp's role deep in the Python application ecosystem, individual flaws can propagate across many dependent applications, making each disclosure relevant to a broader set of defenders than the library's direct product count suggests. Defenders should track this vendor's releases as part of dependency-management routines and prioritize updates for internet-exposed services that rely on the library; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aiohttp over time
Signals from CVEs in this vendor scope (44 CVEs).
44 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-23334HIGH aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the roo | Jan 29, 2024 | 7.5 | 81 | NO | YES |
CVE-2026-34993HIGH AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code ex | Jun 2, 2026 | 7.3 | 35 | NO | NO |
CVE-2026-47265HIGH AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the `cookies` parameter on requests are sent after followi | Jun 2, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-54273HIGH AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on the number of pipelined requests that could be queued. An a | Jun 22, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-54278HIGH AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into | Jun 22, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-54277HIGH AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypass the max_line_size check in parts of an HTTP request in the | Jun 22, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-54274HIGH AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket frame payloads, it may be possible | Jun 22, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-34513HIGH AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resu | Apr 1, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-34520CRITICAL AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and contro | Apr 1, 2026 | 9.1 | 29 | NO | NO |
CVE-2025-69223HIGH AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. A | Jan 5, 2026 | 7.5 | 29 | NO | NO |
Signals from CVEs in this vendor scope (44 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aiohttp.
Media articles that mention a CVE ID that affects a product developed by Aiohttp — matched by CVE ID, not by vendor name.