Known Vulnerabilities for Aiohttp by Aiohttp Project
Listed below are 3 of the newest known vulnerabilities associated with "Aiohttp" by "Aiohttp Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-54280 json | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not cl... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-54279 json | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are s... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-54278 json | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possibl... | Not Provided | 2026-06-22 | 2026-06-23 |
| CVE-2026-54277 json | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypass the... | Not Provided | 2026-06-22 | 2026-06-23 |
| CVE-2026-54276 json | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can sen... | Not Provided | 2026-06-22 | 2026-06-23 |
| CVE-2026-54275 json | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS SNI ... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-54274 json | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large i... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-54273 json | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on the ... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-54008 json | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, backend/op... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-50269 json | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled input in... | Not Provided | 2026-06-22 | 2026-06-22 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Aiohttp Project | Aiohttp | 3.7.4 | |||
| Application | Aiohttp Project | Aiohttp | 3.7.3 | |||
| Application | Aiohttp Project | Aiohttp | 3.7.2 | |||
| Application | Aiohttp Project | Aiohttp | 3.7.1 | |||
| Application | Aiohttp Project | Aiohttp | 3.7.0 | |||
| Application | Aiohttp Project | Aiohttp | 3.7.0 | |||
| Application | Aiohttp Project | Aiohttp | 3.7.0 | |||
| Application | Aiohttp Project | Aiohttp | 3.6.3 | |||
| Application | Aiohttp Project | Aiohttp | 3.6.2 |