{"id":"GHSA-pjjw-qhg8-p2p9","aliases":[],"url":"https://o3.security/vulnerability/GHSA-pjjw-qhg8-p2p9","summary":"aiohttp has vulnerable dependency that is vulnerable to request smuggling","details":"### Summary\nllhttp 8.1.1 is vulnerable to two request smuggling vulnerabilities.\nDetails have not been disclosed yet, so refer to llhttp for future information.\nThe issue is resolved by using llhttp 9+ (which is included in aiohttp 3.8.6+).","published":"2023-11-27T23:15:38Z","modified":"2026-09-10T03:50:04.355249499Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"aiohttp","fixedVersion":"3.8.6"}],"fix":{"url":"https://github.com/aio-libs/aiohttp/commit/996de2629ef6b4c2934a7c04dfd49d0950d4c43b","label":"aio-libs/aiohttp@996de26"},"references":[{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-pjjw-qhg8-p2p9"},{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/commit/996de2629ef6b4c2934a7c04dfd49d0950d4c43b"},{"type":"WEB","url":"https://github.com/aio-libs/aiohttp/commit/bcc416e533796d04fb8124ef1e7686b1f338767a"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:50:04.355249499Z"}}