PT-2026-1357 · Aiohttp+2 · Aiohttp+2

CVE-2025-69230

·

Published

2026-01-05

·

Updated

2026-08-21

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions AIOHTTP versions 3.13.2 and below
Description AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Accessing the cookies attribute in an application with versions 3.13.2 and below can lead to a logging storm when processing multiple invalid cookies. An attacker may be able to trigger a large number of warning-level logs by using a specially crafted Cookie header.
Recommendations Update AIOHTTP to version 3.13.3 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07360
CLEANSTART-2026-AN24336
CLEANSTART-2026-FU07345
CLEANSTART-2026-KE11953
CLEANSTART-2026-NM83456
CLEANSTART-2026-QE89118
CVE-2025-69230
ECHO-EBE2-E1B5-8DBB
GHSA-FH55-R93G-J68G
OPENSUSE-SU-2026:10025-1
PYSEC-2026-1105

Affected Products

Aiohttp
Debian
Red Os