PT-2026-1349 · Aiohttp+4 · Aiohttp+4

Published

2026-01-05

·

Updated

2026-04-20

·

CVE-2025-69224

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AIOHTTP versions 3.13.2 and below
Description AIOHTTP, an asynchronous HTTP client/server framework for asyncio and Python, may be susceptible to a request smuggling attack when using versions 3.13.2 and below. This issue arises from the presence of non-ASCII characters in the Python HTTP parser. If AIOHTTP is installed in a pure Python environment (without C extensions) or with the AIOHTTP NO EXTENSIONS option enabled, an attacker might be able to bypass firewall or proxy protections through this request smuggling attack.
Recommendations Update to AIOHTTP version 3.13.3 or later.

Exploit

Fix

HTTP Request/Response Smuggling

Weakness Enumeration

Related Identifiers

AZL-73497
AZL-73520
BDU:2026-07365
CVE-2025-69224
ECHO-8C97-2DE3-38C8
GHSA-69F9-5GXW-WVC2
OPENSUSE-SU-2026:10025-1
OPENSUSE-SU-2026:20204-1
SUSE-SU-2026:0858-1
SUSE-SU-2026:0859-1
SUSE-SU-2026:20425-1
USN-8032-1

Affected Products

Aiohttp
Debian
Linuxmint
Red Os
Ubuntu