CVE-2025-69223: high-severity vulnerability in aio-libs aiohttp
AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 0.6%
exploitation probability
0.6%top 54% of all CVEs
observed exploitation
nono source reports it
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust the host's memory. This issue is fixed in version 3.13.3.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
aio-libs · aiohttpRelated CVEs — aio-libs aiohttp
In the same product, most dangerous first.
CVE-2024-23334MEDIUMaiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversalEPSS 76.9%CVE-2021-21330LOWOpen redirect vulnerability in aiohttpEPSS 1.9%CVE-2023-37276MEDIUMaiohttp vulnerable to HTTP request smugglingEPSS 1.3%CVE-2024-30251HIGHDenial of service when trying to parse malformed POST requests in aiohttpEPSS 1.1%CVE-2024-23829MEDIUMaiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separatorsEPSS 1.0%CVE-2023-49082MEDIUMaiohttp's ClientSession is vulnerable to CRLF injection via methodEPSS 0.9%
References
https://access.redhat.com/errata/RHSA-2026:10184https://access.redhat.com/errata/RHSA-2026:1249https://access.redhat.com/errata/RHSA-2026:1497https://access.redhat.com/errata/RHSA-2026:1506https://access.redhat.com/errata/RHSA-2026:1596https://access.redhat.com/errata/RHSA-2026:1599https://access.redhat.com/errata/RHSA-2026:1609https://access.redhat.com/errata/RHSA-2026:19712https://access.redhat.com/errata/RHSA-2026:2106https://access.redhat.com/errata/RHSA-2026:2695https://access.redhat.com/errata/RHSA-2026:3461https://access.redhat.com/errata/RHSA-2026:3462