Sam Bull
33 exploits
Active since Jul 2023
AIOHTTP: HTTP request smuggling via WebSocket upgrade
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
AIOHTTP: CRLF injection in multipart headers
CVSS 7.5
AIOHTTP: Incomplete websocket frame payloads bypass memory limits
CVSS 7.5
AIOHTTP Vulnerable to Deserialization of Untrusted Data
CVSS 6.4
AIOHTTP vulnerable to cross-origin redirect with per-request cookies
CVSS 7.5
aiohttp - Directory Traversal
CVSS 5.9
aiohttp < 3.9.4 - Denial of Service via Crafted Multipart Form Data
CVSS 7.5
AIOHTTP: Uncapped memory usage possible through aiohttp allowing unlimited trailer headers
CVSS 7.5
AIOHTTP: Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector
CVSS 7.5
AIOHTTP: CRLF injection in multipart part content type header construction
CVSS 5.3
AIOHTTP: UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows
CVSS 7.5
AIOHTTP: Multipart Header Size Bypass
CVSS 7.5
AIOHTTP: Late size enforcement for non-file multipart fields causes memory DoS
CVSS 5.3
AIOHTTP: Cookie and Proxy-Authorization headers leaked on cross-origin redirect
CVSS 5.3
AIOHTTP: HTTP response splitting via \r in reason phrase
CVSS 5.3
aiohttp < 3.8.5 - HTTP Request Smuggling via llhttp Parser
CVSS 5.3
aiohttp < 3.8.6 - HTTP Request Smuggling via Header Parsing
CVSS 5.3
aiohttp < 3.9.0 - HTTP Request Smuggling via HTTP Version Manipulation
CVSS 7.2
aiohttp < 3.9.0 - HTTP Request Smuggling via CRLF Injection
CVSS 5.3
aiohttp < 3.9.2 - HTTP Request Smuggling via Inconsistent HTTP Parser Validation
CVSS 6.5
aiosmtpd <1.4.5 - SMTP Smuggling Sender Spoofing
CVSS 5.3
aiohttp < 3.9.4 - Cross-Site Scripting in Static File Index Pages
CVSS 6.1
aiohttp < 3.9.4 - Denial of Service via Crafted Multipart Form Data
CVSS 7.5
AIOHTTP <3.12.14 - Request Smuggling
CVSS 7.5