PT-2026-1349 · Aiohttp+4 · Aiohttp+4
Published
2026-01-05
·
Updated
2026-04-20
·
CVE-2025-69224
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
AIOHTTP versions 3.13.2 and below
Description
AIOHTTP, an asynchronous HTTP client/server framework for asyncio and Python, may be susceptible to a request smuggling attack when using versions 3.13.2 and below. This issue arises from the presence of non-ASCII characters in the Python HTTP parser. If AIOHTTP is installed in a pure Python environment (without C extensions) or with the
AIOHTTP NO EXTENSIONS option enabled, an attacker might be able to bypass firewall or proxy protections through this request smuggling attack.Recommendations
Update to AIOHTTP version 3.13.3 or later.
Exploit
Fix
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aiohttp
Debian
Linuxmint
Red Os
Ubuntu