Debian Python-Aiohttp vulnerabilities
22 known vulnerabilities affecting debian/python-aiohttp.
Total CVEs
22
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH3MEDIUM13LOW6
Vulnerabilities
Page 2 of 2
CVE-2025-69225P4LOWCVSS 2.7fixed in python-aiohttp 3.13.3-1 (forky)2025
CVE-2025-69225 [LOW] CVE-2025-69225: python-aiohttp - AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. ...
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the Range header. There is no known impact, but there is the possibility that there's a method to exploit a request smuggling vulnerability. This issue is fixed in version 3.13.3.
Scope:
debian
CVE-2024-42367P4MEDIUMCVSS 4.8fixed in python-aiohttp 3.10.3-2 (forky)2024
CVE-2024-42367 [MEDIUM] CVE-2024-42367: python-aiohttp - aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. ...
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions on the 3.10 branch prior to version 3.10.2, static routes which contain files with compressed variants (`.gz` or `.br` extension) are vulnerable to path traversal outside the root directory if those variants are symbolic links. The server protects static routes from
debian
← Previous2 / 2