Inconsistent interpretation of HTTP requests in aiohttp - #VU153861
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to smuggle HTTP requests.
The vulnerability exists due to improper HTTP request parsing in the aiohttp pure-Python parser when processing HTTP requests. A remote attacker can send crafted HTTP requests to smuggle HTTP requests.
Exposure requires use of the Python parser, including configurations using AIOHTTP_NO_EXTENSIONS or installations without a standard wheel.