CVE-2025-69223
גבוהה 7.5
תיאור (מקור, אנגלית)
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust the host's memory. This issue is fixed in version 3.13.3.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-26/7/2026
- CWE
- CWE-409, CWE-770
מוצרים מושפעים
aiohttp: aiohttp
קישורים
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-6mq8-rvhq-8wgg PatchVendor Advisory
- https://github.com/aio-libs/aiohttp/commit/2b920c39002cee0ec5b402581779bbaaf7c… Patch
- https://access.redhat.com/errata/RHSA-2026:10184
- https://access.redhat.com/errata/RHSA-2026:1249
- https://access.redhat.com/errata/RHSA-2026:1497
- https://access.redhat.com/errata/RHSA-2026:1506
- https://access.redhat.com/errata/RHSA-2026:1596
- https://access.redhat.com/errata/RHSA-2026:1599
- https://access.redhat.com/errata/RHSA-2026:1609
- https://access.redhat.com/errata/RHSA-2026:19712