aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parser is only used when AIOHTTP_NO_EXTENSIONS is enabled (or not using a prebuilt wheel). These bugs have been addressed in commit `d5c12ba89` which has been included in release version 3.8.6. Users are advised to upgrade. There are no known workarounds for these issues.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade python-aiohttp | Dec 16, 2024 | Nov 14, 2023 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.0.10Upgrade Splunk Enterprise to version 9.2.2Upgrade Splunk Enterprise to version 9.1.5 | Sep 30, 2025 | Nov 14, 2023 |
| Suse | — | Upgrade python311-aiohttp | Feb 22, 2024 | Nov 14, 2023 |
| Ubuntu | — | Upgrade python3-aiohttp (Ubuntu Pro) | Jul 11, 2025 | Nov 14, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub