Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-07270

Опубликовано: 06 янв. 2026
Источник: fstec
CVSS3: 7.5
CVSS2: 7.8
EPSS Низкий

Описание

Уязвимость HTTP-клиента aiohttp связана с неограниченным распределением ресурсов. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, вызвать отказ в обслуживании

Вендор

Red Hat Inc.
Сообщество свободного программного обеспечения
ООО «Ред Софт»

Наименование ПО

Openshift Service Mesh
Red Hat Satellite
Red Hat Ansible Automation Platform
Migration Toolkit for Containers
aiohttp
Red Hat OpenShift Lightspeed
Debian GNU/Linux
РЕД ОС
Red Hat AI Inference Server
Red Hat Enterprise Linux AI
Red Hat Ansible Automation Platform Ansible Core
Red Hat OpenShift AI

Версия ПО

2 (Openshift Service Mesh)
6 (Red Hat Satellite)
2 (Red Hat Ansible Automation Platform)
- (Migration Toolkit for Containers)
до 3.10.11 (aiohttp)
- (Red Hat OpenShift Lightspeed)
13 (Debian GNU/Linux)
8.0 (РЕД ОС)
3.2 (Red Hat AI Inference Server)
3 (Red Hat Enterprise Linux AI)
2.6 (Red Hat Ansible Automation Platform)
2 (Red Hat Ansible Automation Platform Ansible Core)
- (Red Hat OpenShift AI)
2.25 (Red Hat OpenShift AI)

Тип ПО

Прикладное ПО информационных систем
Сетевое программное средство
Операционная система

Операционные системы и аппаратные платформы

Сообщество свободного программного обеспечения Debian GNU/Linux 13
ООО «Ред Софт» РЕД ОС 8.0
Red Hat Inc. Red Hat Enterprise Linux AI 3

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 7,8)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 7,5)

Возможные меры по устранению уязвимости

Использование рекомендаций:
https://github.com/aio-libs/aiohttp/commit/b7dbd35375aedbcd712cbae8ad513d56d11cce60
https://github.com/aio-libs/aiohttp/security/advisories/GHSA-6jhg-hg63-jvvf
Для Ред ОС:
https://redos.red-soft.ru/search/?iblock_id=24&q=CVE-2025-69228
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2025-69228
Для Debian GNU/Linux:
https://security-tracker.debian.org/tracker/CVE-2025-69228

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 27%
0.00347
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Связанные уязвимости

CVSS3: 7.5
redos
4 месяца назад

Уязвимость python-aiohttp

CVSS3: 7.5
ubuntu
7 месяцев назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way that an AIOHTTP server's memory fills up uncontrollably during processing. If an application includes a handler that uses the Request.post() method, an attacker may be able to freeze the server by exhausting the memory. This issue is fixed in version 3.13.3.

CVSS3: 6.8
redhat
7 месяцев назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way that an AIOHTTP server's memory fills up uncontrollably during processing. If an application includes a handler that uses the Request.post() method, an attacker may be able to freeze the server by exhausting the memory. This issue is fixed in version 3.13.3.

CVSS3: 7.5
nvd
7 месяцев назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way that an AIOHTTP server's memory fills up uncontrollably during processing. If an application includes a handler that uses the Request.post() method, an attacker may be able to freeze the server by exhausting the memory. This issue is fixed in version 3.13.3.

CVSS3: 7.5
debian
7 месяцев назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

EPSS

Процентиль: 27%
0.00347
Низкий

7.5 High

CVSS3

7.8 High

CVSS2