Sam Bull
25 exploits
Active since Jul 2023
AIOHTTP: Uncapped memory usage possible through aiohttp allowing unlimited trailer headers
CVSS 7.5
AIOHTTP: Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector
CVSS 7.5
AIOHTTP: CRLF injection in multipart part content type header construction
CVSS 5.3
AIOHTTP: UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows
CVSS 7.5
AIOHTTP: Multipart Header Size Bypass
CVSS 7.5
AIOHTTP: Late size enforcement for non-file multipart fields causes memory DoS
CVSS 5.3
AIOHTTP: Cookie and Proxy-Authorization headers leaked on cross-origin redirect
CVSS 5.3
AIOHTTP: HTTP response splitting via \r in reason phrase
CVSS 5.3
Aiohttp < 3.8.4 - HTTP Request Smuggling
CVSS 5.3
Aiohttp < 3.8.6 - HTTP Request Smuggling
CVSS 5.3
aiohttp <3.9.0 - Command Injection
CVSS 7.2
aiohttp - Request Smuggling
CVSS 5.3
Aiohttp < 3.9.2 - HTTP Request Smuggling
CVSS 6.5
aiosmtpd - SSRF
CVSS 5.3
aiohttp <3.9.4 - XSS
CVSS 6.1
Aiohttp < 3.9.4 - Infinite Loop
CVSS 7.5
AIOHTTP <3.12.14 - Request Smuggling
CVSS 7.5
Aiohttp < 3.13.3 - Denial of Service
CVSS 7.5
Aiohttp < 3.13.3 - HTTP Request Smuggling
CVSS 6.5
Aiohttp < 3.13.3 - HTTP Request Smuggling
CVSS 5.3
Aiohttp < 3.13.3 - Information Disclosure
CVSS 5.3
Aiohttp < 3.13.3 - Infinite Loop
CVSS 7.5
Aiohttp < 3.13.3 - Resource Allocation Without Limits
CVSS 7.5
Aiohttp < 3.13.3 - Resource Allocation Without Limits
CVSS 5.3
AIOHTTP <3.13.3 - Info Disclosure
CVSS 5.3