目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1325 CNY

100%

aio-libs 厂商漏洞列表 / CVE 中文分析 38

aio-libs 厂商相关 38 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

aio-libs 是专注于 Python 异步编程生态的开源项目集合,核心提供基于 asyncio 的高性能网络库,如 aiohttp 和 aiomysql。其历史漏洞多集中于反序列化风险、拒绝服务及逻辑缺陷,部分组件曾暴露远程代码执行隐患。鉴于其在 Web 开发中的广泛使用,安全社区对其依赖链风险保持高度关注,建议定期更新以修复已知 CVE,确保异步应用的安全性。

34 件の結果 / 38フィルターをクリア
CVE IDタイトルCVSS深刻度公開日
CVE-2026-47265 AIOHTTP vulnerable to cross-origin redirect with per-request cookies — aiohttpCWE-346--2026-06-02
CVE-2026-34993 AIOHTTP Vulnerable to Deserialization of Untrusted Data — aiohttpCWE-502 6.4 Medium2026-06-02
CVE-2026-34525 AIOHTTP: Duplicate Host header accepted — aiohttpCWE-20 5.8 -2026-04-01
CVE-2026-34520 AIOHTTP: C parser (llhttp) accepts null bytes and control characters in response header values - header injection / security bypass — aiohttpCWE-113 9.1 -2026-04-01
CVE-2026-34519 AIOHTTP: HTTP response splitting via \r in reason phrase — aiohttpCWE-113 6.5 -2026-04-01
CVE-2026-34518 AIOHTTP: Cookie and Proxy-Authorization headers leaked on cross-origin redirect — aiohttpCWE-200 4.3 -2026-04-01
CVE-2026-34517 AIOHTTP: Late size enforcement for non-file multipart fields causes memory DoS — aiohttpCWE-770 7.5 -2026-04-01
CVE-2026-34516 AIOHTTP: Multipart Header Size Bypass — aiohttpCWE-770 7.5 -2026-04-01
CVE-2026-34515 AIOHTTP: UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows — aiohttpCWE-36 5.3 -2026-04-01
CVE-2026-34514 AIOHTTP: CRLF injection in multipart part content type header construction — aiohttpCWE-113 6.5 -2026-04-01
CVE-2026-22815 AIOHTTP: Uncapped memory usage possible through aiohttp allowing unlimited trailer headers — aiohttpCWE-400 7.5 -2026-04-01
CVE-2026-34513 AIOHTTP: Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector — aiohttpCWE-770 7.5AIHighAI2026-04-01
CVE-2025-69230 AIOHTTP Vulnerable to Cookie Parser Warning Storm — aiohttpCWE-779--2026-01-05
CVE-2025-69229 AIOHTTP vulnerable to DoS through chunked messages — aiohttpCWE-770 7.5 -2026-01-05
CVE-2025-69228 AIOHTTP vulnerable to denial of service through large payloads — aiohttpCWE-770 7.5 -2026-01-05
CVE-2025-69227 AIOHTTP vulnerable to DoS when bypassing asserts — aiohttpCWE-835 7.5 -2026-01-05
CVE-2025-69225 AIOHTTP Regex Mismatch Allows Unicode in ASCII-Only Protocol Fields — aiohttpCWE-444 7.5 -2026-01-05
CVE-2025-69226 AIOHTTP allows for a brute-force leak of internal static filepath components — aiohttpCWE-22 5.3 -2026-01-05
CVE-2025-69224 AIOHTTP's Unicode processing of header values could cause parsing discrepancies — aiohttpCWE-444 7.5 -2026-01-05
CVE-2025-69223 AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb — aiohttpCWE-409 7.5 High2026-01-05
CVE-2025-53643 AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections — aiohttpCWE-444 9.8 -2025-07-14
CVE-2024-52304 aiohttp vulnerable to request smuggling due to incorrect parsing of chunk extensions — aiohttpCWE-444 7.5 -2024-11-18
CVE-2024-52303 aiohttp memory leak when middleware is enabled when requesting a resource with a non-allowed method — aiohttpCWE-772 5.9 -2024-11-18
CVE-2024-42367 In aiohttp, compressed files as symlinks are not protected from path traversal — aiohttpCWE-61 4.8 Medium2024-08-09
CVE-2024-30251 Denial of service when trying to parse malformed POST requests in aiohttp — aiohttpCWE-835 7.5 High2024-05-02
CVE-2024-27306 aiohttp vulnerable to XSS on index pages for static file handling — aiohttpCWE-79 6.1 Medium2024-04-18
CVE-2024-23334 aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal — aiohttpCWE-22 5.9 Medium2024-01-29
CVE-2024-23829 aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators — aiohttpCWE-444 6.5 Medium2024-01-29
CVE-2023-49081 aiohttp's ClientSession is vulnerable to CRLF injection via version — aiohttpCWE-20 7.2 High2023-11-30
CVE-2023-49082 aiohttp's ClientSession is vulnerable to CRLF injection via method — aiohttpCWE-93 5.3 Medium2023-11-29

本页汇总了 aio-libs 厂商截至目前公开的全部 38 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。