Skip to main content

Checkov: aiohttp has vulnerable dependency that is vulnerable to request smuggling

0
High
Published: 08/13/2026 (08/13/2026, 16:39:32 UTC)
Source: GCVE Database
Product: checkov

Description

The llhttp library version 8.1.1 contains two request smuggling vulnerabilities. These vulnerabilities affect aiohttp versions prior to 3.8.6 because they include the vulnerable llhttp version. The vulnerabilities are resolved by upgrading to llhttp version 9 or later, which is included in aiohttp 3.8.6 and above. The affected product Checkov uses aiohttp versions from 2.0.615 up to but not including 2.5.10, which rely on the vulnerable llhttp version. No detailed technical information or exploitation details have been disclosed yet.

Affected software

Homebrewmore threats →ghsa
checkov
pkg:brew/checkov
Affected versions
>=2.0.615 <2.5.10

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/18/2026, 01:37:49 UTC

Technical Analysis

llhttp 8.1.1 has two undisclosed request smuggling vulnerabilities. aiohttp versions prior to 3.8.6 include this vulnerable llhttp version. Checkov versions >=2.0.615 and <2.5.10 depend on these vulnerable aiohttp versions. The issue is fixed by upgrading to llhttp 9+, which is included in aiohttp 3.8.6 and later.

Potential Impact

The vulnerabilities could allow HTTP request smuggling attacks in affected versions of aiohttp used by Checkov. No known exploits are reported in the wild. The impact details have not been disclosed, so the precise consequences are currently unknown.

Mitigation Recommendations

Upgrade aiohttp to version 3.8.6 or later, which includes llhttp 9 or newer, resolving the vulnerabilities. For Checkov, upgrade to a version that uses aiohttp 3.8.6+ or later. Since a patch is available, applying the official fix is the recommended mitigation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
BREW-checkov-GHSA-pjjw-qhg8-p2p9
Osv Schema Version
1.7.3
Ecosystems
["Homebrew"]

Threat ID: 6aac8e1d55bf5e2cf549073c

Added to database: 09/18/2026, 01:04:29 UTC

Last enriched: 09/18/2026, 01:37:49 UTC

Last updated: 09/18/2026, 03:01:24 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses