PT-2026-1351 · Aiohttp+4 · Aiohttp+4
Published
2026-01-05
·
Updated
2026-04-20
·
CVE-2025-69226
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
AIOHTTP versions 3.13.2 and below
Description
AIOHTTP, an asynchronous HTTP client/server framework for asyncio and Python, has an issue where versions 3.13.2 and below allow an attacker to determine the existence of absolute path components through the path normalization logic for static files. This is related to the use of the
web.static() function, which is not recommended for production deployments. An attacker may be able to determine the existence of path components within the system.Recommendations
Update to version 3.13.3 or later.
Exploit
Fix
Information Disclosure
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aiohttp
Debian
Linuxmint
Red Os
Ubuntu