aiohttp
PyPIaiohttpaiohttp is an async HTTP client and server library for Python built on asyncio. It is used in high-throughput Python services, web scrapers, and as the server component of some web frameworks. Many LangChain integrations use aiohttp for async API calls to external services.
Checking aiohttp
aiohttp 3.10.0 is a clean, monitored version with no known supply chain compromise. The example response returns supply_chain_monitored: true and compromised: false with an empty sources array.
curl "https://api.attestd.io/v1/check?product=aiohttp&version=3.10.0" \
-H "Authorization: Bearer YOUR_API_KEY"{
"product": "aiohttp",
"version": "3.10.0",
"supported": true,
"risk_state": "none",
"risk_factors": [],
"actively_exploited": false,
"remote_exploitable": false,
"authentication_required": false,
"patch_available": false,
"fixed_version": null,
"confidence": 0.9,
"cve_ids": [],
"cves": null,
"max_epss": null,
"typosquat": null,
"supply_chain_monitored": true,
"supply_chain": {
"compromised": false,
"sources": [],
"malware_type": null,
"description": null,
"advisory_url": null,
"compromised_at": null,
"removed_at": null
},
"last_updated": "2026-05-01T00:00:00Z"
}Why this package is monitored
aiohttp multiplexes concurrent client and server traffic on one event loop, including many LangChain async integrations. A hostile build can harvest tokens and payloads across parallel in-flight requests.
Attestd monitors aiohttp using the following detection sources:
registryManually curated advisories in the Attestd registry, verified by a human analyst. Confidence 1.0.
osvOSV.dev malicious-package advisories with IDs prefixed MAL-. Confidence 0.95.
pypi_yankVersions yanked on PyPI with a security-related yanked_reason annotation. Confidence 0.80.