Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-07193

Опубликовано: 05 янв. 2026
Источник: fstec
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

Уязвимость HTTP-клиента aiohttp связана с отсутствием защиты служебных данных. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, получить несанкционированный доступ к защищаемой информации

Вендор

Canonical Ltd.
Red Hat Inc.
ООО «Ред Софт»
Сообщество свободного программного обеспечения

Наименование ПО

Ubuntu
Openshift Service Mesh
РЕД ОС
Red Hat Satellite
Migration Toolkit for Containers
Red Hat Enterprise Linux AI
Red Hat OpenShift Lightspeed
Red Hat AI Inference Server
Debian GNU/Linux
Ansible Automation Platform
Red Hat OpenShift AI
aiohttp

Версия ПО

18.04 LTS (Ubuntu)
20.04 LTS (Ubuntu)
2 (Openshift Service Mesh)
7.3 (РЕД ОС)
6 (Red Hat Satellite)
22.04 LTS (Ubuntu)
- (Migration Toolkit for Containers)
24.04 LTS (Ubuntu)
- (Red Hat Enterprise Linux AI)
- (Red Hat OpenShift Lightspeed)
- (Red Hat AI Inference Server)
13 (Debian GNU/Linux)
25.10 (Ubuntu)
8.0 (РЕД ОС)
2 (Ansible Automation Platform)
- (Red Hat OpenShift AI)
до 3.13.3 (aiohttp)

Тип ПО

Операционная система
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

Canonical Ltd. Ubuntu 18.04 LTS
Canonical Ltd. Ubuntu 20.04 LTS
ООО «Ред Софт» РЕД ОС 7.3
Canonical Ltd. Ubuntu 22.04 LTS
Canonical Ltd. Ubuntu 24.04 LTS
Red Hat Inc. Red Hat Enterprise Linux AI -
Сообщество свободного программного обеспечения Debian GNU/Linux 13
Canonical Ltd. Ubuntu 25.10
ООО «Ред Софт» РЕД ОС 8.0

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 5)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 5,3)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://github.com/aio-libs/aiohttp/security/advisories/GHSA-54jq-c3m8-4m76
Для РедОС:
https://redos.red-soft.ru/search/?iblock_id=24&q=CVE-2025-69226
Для Debian GNU/Linux:
https://security-tracker.debian.org/tracker/CVE-2025-69226
Для Ubuntu:
https://ubuntu.com/security/CVE-2025-69226
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2025-69226

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 24%
0.00313
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.3
redos
4 месяца назад

Уязвимость python-aiohttp

CVSS3: 5.3
ubuntu
7 месяцев назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.

CVSS3: 5.3
redhat
7 месяцев назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.

CVSS3: 5.3
nvd
7 месяцев назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.

CVSS3: 5.3
debian
7 месяцев назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

EPSS

Процентиль: 24%
0.00313
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2