PT-2026-1349 · Aiohttp+4 · Aiohttp+4

CVE-2025-69224

·

Published

2026-01-05

·

Updated

2026-08-21

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AIOHTTP versions 3.13.2 and below
Description AIOHTTP, an asynchronous HTTP client/server framework for asyncio and Python, may be susceptible to a request smuggling attack when using versions 3.13.2 and below. This issue arises from the presence of non-ASCII characters in the Python HTTP parser. If AIOHTTP is installed in a pure Python environment (without C extensions) or with the AIOHTTP NO EXTENSIONS option enabled, an attacker might be able to bypass firewall or proxy protections through this request smuggling attack.
Recommendations Update to AIOHTTP version 3.13.3 or later.

Exploit

Fix

DoS

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-73497
AZL-73520
BDU:2026-07365
CLEANSTART-2026-AN24336
CLEANSTART-2026-FU07345
CLEANSTART-2026-KE11953
CLEANSTART-2026-NM83456
CLEANSTART-2026-QE89118
CVE-2025-69224
ECHO-8C97-2DE3-38C8
GHSA-69F9-5GXW-WVC2
OPENSUSE-SU-2026:10025-1
OPENSUSE-SU-2026:20204-1
PYSEC-2026-1099
SUSE-SU-2026:0858-1
SUSE-SU-2026:0859-1
SUSE-SU-2026:20425-1
USN-8032-1

Affected Products

Aiohttp
Debian
Linuxmint
Red Os
Ubuntu