Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mqqc-3gqh-h2x8

Опубликовано: 05 янв. 2026
Источник: github
Github: Прошло ревью
CVSS4: 2.7

Описание

AIOHTTP has unicode match groups in regexes for ASCII protocol elements

Summary

The parser allows non-ASCII decimals to be present in the Range header.

Impact

There is no known impact, but there is the possibility that there's a method to exploit a request smuggling vulnerability.


Patch: https://github.com/aio-libs/aiohttp/commit/c7b7a044f88c71cefda95ec75cdcfaa4792b3b96

Пакеты

Наименование

aiohttp

pip
Затронутые версииВерсия исправления

<= 3.13.2

3.13.3

EPSS

Процентиль: 18%
0.00055
Низкий

2.7 Low

CVSS4

Дефекты

CWE-444

Связанные уязвимости

ubuntu
10 дней назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the Range header. There is no known impact, but there is the possibility that there's a method to exploit a request smuggling vulnerability. This issue is fixed in version 3.13.3.

nvd
10 дней назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the Range header. There is no known impact, but there is the possibility that there's a method to exploit a request smuggling vulnerability. This issue is fixed in version 3.13.3.

debian
10 дней назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

EPSS

Процентиль: 18%
0.00055
Низкий

2.7 Low

CVSS4

Дефекты

CWE-444