PT-2026-1348 · Aiohttp+4 · Aiohttp+4
Published
2026-01-05
·
Updated
2026-04-20
·
CVE-2025-69223
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
AIOHTTP versions 3.13.2 and below
Description
AIOHTTP, an asynchronous HTTP client/server framework for asyncio and Python, is susceptible to a denial-of-service (DoS) attack. An attacker can send a compressed request, specifically a zip bomb, that when decompressed by AIOHTTP, exhausts the host's memory. This could lead to service disruption.
Recommendations
Update AIOHTTP to version 3.13.3 or later.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aiohttp
Debian
Linuxmint
Red Os
Ubuntu