Aio-Libs Aiohttp vulnerabilities
42 known vulnerabilities affecting aio-libs/aiohttp.
Total CVEs
42
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH24MEDIUM17
Vulnerabilities
Page 3 of 3
CVE-2024-27306P4MEDIUMCVSS 6.1fixed in 3.9.42024-04-18
CVE-2024-27306 [MEDIUM] CWE-79 CVE-2024-27306: aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disab
nvd
CVE-2024-42367P4MEDIUMCVSS 4.8v>= 3.10.0b1, < 3.10.22024-08-12
CVE-2024-42367 [MEDIUM] CWE-61 CVE-2024-42367: aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions on the 3
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions on the 3.10 branch prior to version 3.10.2, static routes which contain files with compressed variants (`.gz` or `.br` extension) are vulnerable to path traversal outside the root directory if those variants are symbolic links. The server protects static route
nvd
← Previous3 / 3