Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-07337

Опубликовано: 05 янв. 2026
Источник: fstec
CVSS3: 7.5
CVSS2: 7.8
EPSS Низкий

Описание

Уязвимость HTTP-клиента aiohttp связана с некорректной обработкой сильно сжатых входных данных. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, вызвать отказ в обслуживании

Вендор

Red Hat Inc.
Сообщество свободного программного обеспечения
ООО «Ред Софт»

Наименование ПО

Red Hat Satellite
Red Hat Ansible Automation Platform
Migration Toolkit for Containers
aiohttp
Red Hat OpenShift Lightspeed
Red Hat AI Inference Server
Debian GNU/Linux
РЕД ОС
Red Hat Ansible Automation Platform Ansible Core
Red Hat OpenShift AI

Версия ПО

6 (Red Hat Satellite)
2 (Red Hat Ansible Automation Platform)
- (Migration Toolkit for Containers)
2.4 (Red Hat Ansible Automation Platform)
до 3.10.11 (aiohttp)
2.4 for RHEL 8 (Red Hat Ansible Automation Platform)
2.4 for RHEL 9 (Red Hat Ansible Automation Platform)
- (Red Hat OpenShift Lightspeed)
2.5 for RHEL 8 (Red Hat Ansible Automation Platform)
2.5 for RHEL 9 (Red Hat Ansible Automation Platform)
- (Red Hat AI Inference Server)
13 (Debian GNU/Linux)
8.0 (РЕД ОС)
3.2 (Red Hat AI Inference Server)
2.6 for RHEL 9 (Red Hat Ansible Automation Platform)
2.5 (Red Hat Ansible Automation Platform)
2.6 (Red Hat Ansible Automation Platform)
2 (Red Hat Ansible Automation Platform Ansible Core)
- (Red Hat OpenShift AI)
2.25 (Red Hat OpenShift AI)
3.3 (Red Hat OpenShift AI)

Тип ПО

Прикладное ПО информационных систем
Сетевое программное средство
Операционная система

Операционные системы и аппаратные платформы

Сообщество свободного программного обеспечения Debian GNU/Linux 13
ООО «Ред Софт» РЕД ОС 8.0

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 7,8)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 7,5)

Возможные меры по устранению уязвимости

Использование рекомендаций:
https://github.com/aio-libs/aiohttp/commit/2b920c39002cee0ec5b402581779bbaaf7c9138a
https://github.com/aio-libs/aiohttp/security/advisories/GHSA-6mq8-rvhq-8wgg
Для Ред ОС:
https://redos.red-soft.ru/search/?iblock_id=24&q=CVE-2025-69223
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2025-69223
Для Debian GNU/Linux:
https://security-tracker.debian.org/tracker/CVE-2025-69223

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 40%
0.00505
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Связанные уязвимости

CVSS3: 7.5
redos
4 месяца назад

Уязвимость python-aiohttp

CVSS3: 7.5
ubuntu
7 месяцев назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust the host's memory. This issue is fixed in version 3.13.3.

CVSS3: 7.5
redhat
7 месяцев назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust the host's memory. This issue is fixed in version 3.13.3.

CVSS3: 7.5
nvd
7 месяцев назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust the host's memory. This issue is fixed in version 3.13.3.

CVSS3: 7.5
debian
7 месяцев назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

EPSS

Процентиль: 40%
0.00505
Низкий

7.5 High

CVSS3

7.8 High

CVSS2