3.14.1
12 years ago
14 days ago
Known vulnerabilities in the aiohttp package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling through the handling of HTTP/1 pipelined requests queue without a limit. An attacker can exhaust system memory by sending a large number of pipelined requests, potentially causing service disruption. How to fix Allocation of Resources Without Limits or Throttling? Upgrade | [,3.14.1) |
Affected versions of this package are vulnerable to Improper Resource Shutdown or Release in the payload response resources when a client disconnects during a write operation. An attacker can cause temporary resource exhaustion by repeatedly initiating connections and disconnecting mid-transfer, leading to open files or similar resources not being released until garbage collection occurs. How to fix Improper Resource Shutdown or Release? Upgrade | [,3.14.1) |
Affected versions of this package are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) during cleanup. An attacker can exhaust system memory by sending a specially crafted compressed payload that is decompressed into memory in a single chunk. How to fix Improper Handling of Highly Compressed Data (Data Amplification)? Upgrade | [,3.14.1) |
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling in the How to fix Allocation of Resources Without Limits or Throttling? Upgrade | [,3.14.1) |
Affected versions of this package are vulnerable to Improper Validation of Certificate with Host Mismatch in the How to fix Improper Validation of Certificate with Host Mismatch? Upgrade | [,3.14.1) |
Affected versions of this package are vulnerable to Exposure of Private Personal Information to an Unauthorized Actor in the How to fix Exposure of Private Personal Information to an Unauthorized Actor? Upgrade | [,3.14.1) |
Affected versions of this package are vulnerable to Insufficiently Protected Credentials via the Note: This is only exploitable if the client follows redirects to attacker-controlled domains. How to fix Insufficiently Protected Credentials? Upgrade | [,3.14.1) |
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the How to fix Allocation of Resources Without Limits or Throttling? Upgrade | [,3.14.1) |