Headline
GHSA-pjjw-qhg8-p2p9: aiohttp has vulnerable dependency that is vulnerable to request smuggling
Summary
llhttp 8.1.1 is vulnerable to two request smuggling vulnerabilities. Details have not been disclosed yet, so refer to llhttp for future information. The issue is resolved by using llhttp 9+ (which is included in aiohttp 3.8.6+).
aiohttp has vulnerable dependency that is vulnerable to request smuggling
Moderate severity GitHub Reviewed Published Nov 25, 2023 in aio-libs/aiohttp • Updated Nov 27, 2023