Vulnerabilidades en aio-libs
50 resultadosAnálisis Vexday
A aio-libs acumula 47 CVEs na base, sendo 11 publicadas nos últimos 90 dias, o que indica ritmo consistente de descobertas. Nenhuma vulnerabilidade está sob ataque ativo e não há críticas confirmadas, reduzindo pressão imediata, mas a fraqueza dominante (CWE-770 - alocação de recursos sem limite) sugere problemas estruturais de consumo de recursos que demandam atenção.
CVE-2026-54278MEDIUMAIOHTTP: Unread Compressed Request Bodies Bypass client_max_size During CleanupEPSS 0.4%CVE-2026-34517LOWAIOHTTP: Late size enforcement for non-file multipart fields causes memory DoSEPSS 0.4%CVE-2024-27305MEDIUMSMTP smuggling in aiosmtpdEPSS 0.4%CVE-2025-62611HIGHaiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL serverEPSS 0.4%CVE-2025-69228MEDIUMAIOHTTP vulnerable to denial of service through large payloadsEPSS 0.4%CVE-2025-69229MEDIUMAIOHTTP vulnerable to DoS through chunked messagesEPSS 0.4%CVE-2025-69227MEDIUMAIOHTTP vulnerable to DoS when bypassing assertsEPSS 0.3%CVE-2025-69230LOWAIOHTTP Vulnerable to Cookie Parser Warning StormEPSS 0.3%CVE-2026-34518LOWAIOHTTP: Cookie and Proxy-Authorization headers leaked on cross-origin redirectEPSS 0.3%CVE-2026-54277MEDIUMAIOHTTP: C HTTP Parser Bypasses max_line_size for Fragmented LinesEPSS 0.3%CVE-2025-69226MEDIUMAIOHTTP allows for a brute-force leak of internal static filepath componentsEPSS 0.3%CVE-2026-34514LOWAIOHTTP: CRLF injection in multipart part content type header constructionEPSS 0.3%CVE-2026-54274MEDIUMAIOHTTP: Incomplete websocket frame payloads bypass memory limitsEPSS 0.3%CVE-2026-59881MEDIUMAIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflateEPSS 0.3%CVE-2026-50269LOWAIOHTTP: CRLF injection in multipart headersEPSS 0.3%CVE-2026-69244HIGHAIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)EPSS 0.3%CVE-2025-53643LOWAIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sectionsEPSS 0.3%CVE-2026-34519LOWAIOHTTP: HTTP response splitting via \r in reason phraseEPSS 0.3%CVE-2026-34525MEDIUMAIOHTTP: Duplicate Host header acceptedEPSS 0.3%CVE-2026-54280LOWAIOHTTP: Payload Response Resources Are Not Closed After Mid-Body DisconnectEPSS 0.3%