Is aiohttp healthy, maintained, and safe?
Maintained, but watch it — aiohttp has real signals (drift, thin maintenance, or advisories) worth tracking.
The verdict
OSPulse scores aiohttp at 55/100 (medium risk), computed deterministically from live PyPI release history, and the OSV vulnerability database. Maintained, but watch it — aiohttp has real signals (drift, thin maintenance, or advisories) worth tracking.
Its most recent release shipped on 23 July 2026 — 4 days ago — so development is clearly active. Across 305 releases the cadence has been steady, which is a good sign of an ongoing maintenance rhythm. PyPI doesn't expose a reliable maintainer count, so bus-factor isn't scored here — treat maintenance depth as unknown rather than assumed.
OSV lists 87 known advisories for aiohttp, including 3 high. Review whether your version is in the affected range and whether a fixed release is available before depending on it. Each advisory is listed with its OSV/GHSA identifier below.
aiohttp is usable but carries real signals — pin versions, watch for new advisories, and keep a fallback in mind. This is a one-time snapshot of a single package — real projects depend on dozens or hundreds of packages, and any one of them can drift or be compromised between releases. Run your own requirements.txt through the free health check, or have OSPulse monitor your whole dependency tree continuously.
Evidence trail — deterministic, auditable
Known vulnerabilities (87)
aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method
aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence
AIOHTTP has CRLF injection through multipart part content type header construction
AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS
aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parser
aiohttp: HTTP/1 Pipelined Requests Queue Without Limit
aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
AIOHTTP vulnerable to brute-force leak of internal static file path components
aiohttp is vulnerable to directory traversal
aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests
AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass
aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines
AIOHTTP's unicode processing of header values could cause parsing discrepancies
AIOHTTP vulnerable to denial of service through large payloads
AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
aiohttp Cross-site Scripting vulnerability on index pages for static file handling
aiohttp allows request smuggling due to incorrect parsing of chunk extensions
aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators
AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect
aiohttp: Payload Response Resources Are Not Closed After Mid-Body Disconnect
AIOHTTP accepts duplicate Host headers
AIOHTTP Vulnerable to Cookie Parser Warning Storm
aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup
AIOHTTP vulnerable to DoS through chunked messages
AIOHTTP has problems in HTTP parser (the python one, not llhttp)
AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector
AIOHTTP is vulnerable to cross-origin redirect with per-request cookies
aiohttp: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges
AIOHTTP is Vulnerable to Deserialization of Untrusted Data
AIOHTTP vulnerable to DoS when bypassing asserts
In aiohttp, compressed files as symlinks are not protected from path traversal
AIOHTTP has a Multipart Header Size Bypass
aiohttp: CRLF injection in multipart headers
AIOHTTP has unicode match groups in regexes for ASCII protocol elements
AIOHTTP has HTTP response splitting via \r in reason phrase
AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows
- GHSA-pjjw-qhg8-p2p9 ↗MODERATE
aiohttp has vulnerable dependency that is vulnerable to request smuggling
aiohttp's ClientSession is vulnerable to CRLF injection via version
aiohttp's ClientSession is vulnerable to CRLF injection via method
`aiohttp` Open Redirect vulnerability (`normalize_path_middleware` middleware)
aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage
aiohttp: Incomplete websocket frame payloads bypass memory limits
Aiohttp has inconsistent interpretation of `Content-Length` vs. `Transfer-Encoding` differing in C and Python fallbacks
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In aiohttp before version 3.7.4 there is an open redirect vulnerability. A maliciously crafted link to an aiohttp-based
aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parser
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parser
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Affected versions of aiohttp have a security vulnerability regarding the inconsistent interpretation of the http protoco
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for an attacker to modify the HTTP request (e.g. to insert a new header) or create
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even crea
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static fi
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must tri
aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method
AIOHTTP vulnerable to brute-force leak of internal static file path components
aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests
AIOHTTP's unicode processing of header values could cause parsing discrepancies
AIOHTTP vulnerable to denial of service through large payloads
AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
aiohttp Cross-site Scripting vulnerability on index pages for static file handling
aiohttp allows request smuggling due to incorrect parsing of chunk extensions
AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
AIOHTTP Vulnerable to Cookie Parser Warning Storm
AIOHTTP vulnerable to DoS through chunked messages
AIOHTTP vulnerable to DoS when bypassing asserts
In aiohttp, compressed files as symlinks are not protected from path traversal
AIOHTTP has unicode match groups in regexes for ASCII protocol elements
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This is
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situa
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the content_type parameter in aiohttp could use this to inject extra h
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the static resource handler may expose information about a NTLMv2 remote path. This
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, a response with an excessive number of multipart headers may be allowed to use more memory than
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, for some multipart form fields, aiohttp read the entire field into memory before checking clien
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, when following redirects to a different origin, aiohttp drops the Authorization header, but ret
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the reason parameter when creating a Response may be able to inject ex
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in resp
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4.
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applic
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the `cookies` parameter on requests are sent after following a cross-origin re
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled input included into multipart/payload headers can be used to modify a request to in
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on the number of pipelined requests that could be queued. An attacker may be able
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypass the max_line_size check in parts of an HTTP request in the C parser. If using
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lo
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a pay
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS SNI check can be bypassed when an existing connection is reused. If an applicat
Key facts
- Latest version
- v3.14.3
- Last release
- 23 July 2026 (4 days ago)
- Total releases
- 305
- First release
- 25 October 2013
- Package age
- 12.8 years
- Maintainers
- not exposed by PyPI
- Known advisories
- 87
- Confidence
- High
Frequently asked
Is aiohttp still maintained?
Yes — aiohttp released as recently as 23 July 2026 (4 days ago), so it is actively maintained.
Does aiohttp have known security vulnerabilities?
Yes — OSV lists 87 advisories for aiohttp. See the advisory list on this page for the OSV/GHSA identifiers.
Is aiohttp safe to use?
Maintained, but watch it — aiohttp has real signals (drift, thin maintenance, or advisories) worth tracking. OSPulse rates it 55/100 (medium risk) based on release recency, cadence and known vulnerabilities.
Other PyPI packages we've checked
aiohttp is one package. What about the other hundreds in your tree?
Paste your own requirements.txt into the free health check for an instant snapshot — or let OSPulse monitor your whole dependency tree continuously, before your CVE scanner wakes up.
Data from the PyPI registry & OSV.dev · snapshot generated 2026-07-27 · scores are deterministic and recomputed on each refresh.
