HIGH🇵🇱 Wersja polska

CVE-2023-49081

CVSS 7.2v3.1pub. 2023-11-30upd. 2026-06-23

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for an attacker to modify the HTTP request (e.g. to insert a new header) or create a new HTTP request if the attacker controls the HTTP version. The vulnerability only occurs if the attacker can control the HTTP version of the request. This issue has been patched in version 3.9.0.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
  • Aiohttp

    APP
    Aiohttp
    < 3.9.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-69223HIGH7.5same product

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allo...

CVE-2024-52303HIGH8.7same product

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions starting with 3.10...

CVE-2024-30251HIGH7.5same product

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attack...

CVE-2026-54273MEDIUM6.6same product

AIOHTTP to asynchroniczny framework klienta/serwera HTTP dla asyncio i Python. Przed wersją 3.14.1 brak był li...

CVE-2026-54274MEDIUM6.6same product

AIOHTTP to asynchroniczny framework HTTP client/server dla asyncio i Pythona. Przed wersją 3.14.1 atakujący mó...