Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6jhg-hg63-jvvf

Опубликовано: 05 янв. 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.6

Описание

AIOHTTP vulnerable to denial of service through large payloads

Summary

A request can be crafted in such a way that an aiohttp server's memory fills up uncontrollably during processing.

Impact

If an application includes a handler that uses the Request.post() method, an attacker may be able to freeze the server by exhausting the memory.


Patch: https://github.com/aio-libs/aiohttp/commit/b7dbd35375aedbcd712cbae8ad513d56d11cce60

Пакеты

Наименование

aiohttp

pip
Затронутые версииВерсия исправления

<= 3.13.2

3.13.3

EPSS

Процентиль: 19%
0.0006
Низкий

6.6 Medium

CVSS4

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way that an AIOHTTP server's memory fills up uncontrollably during processing. If an application includes a handler that uses the Request.post() method, an attacker may be able to freeze the server by exhausting the memory. This issue is fixed in version 3.13.3.

CVSS3: 7.5
nvd
около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way that an AIOHTTP server's memory fills up uncontrollably during processing. If an application includes a handler that uses the Request.post() method, an attacker may be able to freeze the server by exhausting the memory. This issue is fixed in version 3.13.3.

CVSS3: 7.5
debian
около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

EPSS

Процентиль: 19%
0.0006
Низкий

6.6 Medium

CVSS4

Дефекты

CWE-770