PT-2026-1351 · Aiohttp+4 · Aiohttp+4

Published

2026-01-05

·

Updated

2026-04-20

·

CVE-2025-69226

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions AIOHTTP versions 3.13.2 and below
Description AIOHTTP, an asynchronous HTTP client/server framework for asyncio and Python, has an issue where versions 3.13.2 and below allow an attacker to determine the existence of absolute path components through the path normalization logic for static files. This is related to the use of the web.static() function, which is not recommended for production deployments. An attacker may be able to determine the existence of path components within the system.
Recommendations Update to version 3.13.3 or later.

Exploit

Fix

Information Disclosure

Path traversal

Weakness Enumeration

Related Identifiers

AZL-73503
AZL-73526
BDU:2026-07193
CVE-2025-69226
ECHO-7081-D4CF-1BF4
GHSA-54JQ-C3M8-4M76
OPENSUSE-SU-2026:10025-1
OPENSUSE-SU-2026:20204-1
SUSE-SU-2026:0858-1
SUSE-SU-2026:0859-1
SUSE-SU-2026:20425-1
USN-8032-1

Affected Products

Aiohttp
Debian
Linuxmint
Red Os
Ubuntu