Known Vulnerabilities for Aiohttp by Aiohttp Project
Listed below are 3 of the newest known vulnerabilities associated with "Aiohttp" by "Aiohttp Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-88001 json | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 until 0.11.1, server-side we... | Not Provided | 2026-09-09 | 2026-09-10 |
| CVE-2026-85242 json | PlaywrightCapture contains a server-side request forgery (SSRF) vulnerability in its favicon retrieval functionality. When on... | Not Provided | 2026-09-03 | 2026-09-03 |
| CVE-2026-73210 json | A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo's PlaywrightCapture when the only_global_lookup option... | Not Provided | 2026-08-11 | 2026-08-12 |
| CVE-2026-72848 json | SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain... | Not Provided | 2026-08-20 | 2026-09-24 |
| CVE-2026-69244 json | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read c... | Not Provided | 2026-08-03 | 2026-08-04 |
| CVE-2026-69243 json | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were vulner... | Not Provided | 2026-08-03 | 2026-08-05 |
| CVE-2026-59881 json | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client accepts... | Not Provided | 2026-07-30 | 2026-07-30 |
| CVE-2026-48809 json | python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two spe... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-37237 json | vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. The AsyncMediaIO.... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-34993 json | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.lo... | Not Provided | 2026-06-02 | 2026-09-04 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Aiohttp Project | Aiohttp | 3.7.4 | |||
| Application | Aiohttp Project | Aiohttp | 3.7.3 | |||
| Application | Aiohttp Project | Aiohttp | 3.7.2 | |||
| Application | Aiohttp Project | Aiohttp | 3.7.1 | |||
| Application | Aiohttp Project | Aiohttp | 3.7.0 | |||
| Application | Aiohttp Project | Aiohttp | 3.7.0 | |||
| Application | Aiohttp Project | Aiohttp | 3.7.0 | |||
| Application | Aiohttp Project | Aiohttp | 3.6.3 | |||
| Application | Aiohttp Project | Aiohttp | 3.6.2 |