Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mqqc-3gqh-h2x8

Опубликовано: 05 янв. 2026
Источник: github
Github: Прошло ревью
CVSS4: 2.7

Описание

AIOHTTP has unicode match groups in regexes for ASCII protocol elements

Summary

The parser allows non-ASCII decimals to be present in the Range header.

Impact

There is no known impact, but there is the possibility that there's a method to exploit a request smuggling vulnerability.


Patch: https://github.com/aio-libs/aiohttp/commit/c7b7a044f88c71cefda95ec75cdcfaa4792b3b96

Пакеты

Наименование

aiohttp

pip
Затронутые версииВерсия исправления

<= 3.13.2

3.13.3

EPSS

Процентиль: 16%
0.00245
Низкий

2.7 Low

CVSS4

Дефекты

CWE-444

Связанные уязвимости

CVSS3: 5.3
ubuntu
7 месяцев назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the Range header. There is no known impact, but there is the possibility that there's a method to exploit a request smuggling vulnerability. This issue is fixed in version 3.13.3.

CVSS3: 5.4
redhat
7 месяцев назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the Range header. There is no known impact, but there is the possibility that there's a method to exploit a request smuggling vulnerability. This issue is fixed in version 3.13.3.

CVSS3: 5.3
nvd
7 месяцев назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the Range header. There is no known impact, but there is the possibility that there's a method to exploit a request smuggling vulnerability. This issue is fixed in version 3.13.3.

CVSS3: 5.3
debian
7 месяцев назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

CVSS3: 5.3
fstec
7 месяцев назад

Уязвимость HTTP-клиента aiohttp, связанная с недостатками обработки http-запросов, позволяющая нарушителю отправить скрытый HTTP-запрос (атака типа HTTP Request Smuggling)

EPSS

Процентиль: 16%
0.00245
Низкий

2.7 Low

CVSS4

Дефекты

CWE-444