CVE security advisories and vulnerability history for aiohttp by aio-libs.
44
Total CVEs
Published
0
In CISA KEV
Exploited in the wild
5
Public exploits
PoC or exploit code
5.4
Avg CVSS
2021–2026
Last updated
Overview
aio-libs aiohttp has 44 published CVE records since 2021, of which 0 are in CISA's Known Exploited Vulnerabilities catalog and 5 have a known public exploit. The average CVSS base score across scored CVEs is 5.4.
This page aggregates every publicly disclosed vulnerability (CVE) affecting aio-libs aiohttp, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of aio-libs aiohttp's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical0
High8
Medium23
Low13
In CISA’s Known Exploited Vulnerabilities catalog
0
None of aio-libs aiohttp's CVEs are currently listed in CISA's KEV catalog.
Public exploits
5
5 of aio-libs aiohttp's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every aio-libs aiohttp version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about aio-libs aiohttp vulnerabilities.
How many CVEs does aio-libs aiohttp have?
aio-libs aiohttp has 44 published CVE records since 2021.
How many aio-libs aiohttp CVEs are in CISA KEV?
None of aio-libs aiohttp's CVEs are currently listed in CISA's Known Exploited Vulnerabilities catalog.
Are there public exploits for aio-libs aiohttp vulnerabilities?
Yes — 5 of aio-libs aiohttp's CVEs have a known public exploit.
Which versions of aio-libs aiohttp are affected?
248 distinct aio-libs aiohttp versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in aio-libs aiohttp CVEs?
aio-libs aiohttp's CVEs most often map to these CWE weakness types: CWE-770 (Allocation of Resources Without Limits or Throttling), CWE-444 (Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')), CWE-113 (Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')), CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor).
What is the average severity of aio-libs aiohttp CVEs?
The average CVSS base score across aio-libs aiohttp's scored CVEs is 5.4.