Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-69225

Опубликовано: 05 янв. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the Range header. There is no known impact, but there is the possibility that there's a method to exploit a request smuggling vulnerability. This issue is fixed in version 3.13.3.

A flaw was found in aiohttp, an asynchronous HTTP client/server framework. The parser logic allows non-ASCII decimal characters in the HTTP Range header. This could potentially enable a remote attacker to exploit a request smuggling vulnerability, leading to the bypass of security controls or unauthorized information access.

Отчет

This vulnerability is rated Low for Red Hat products as it affects components utilizing the aiohttp framework, including Red Hat AI Inference Server, Red Hat Ansible Automation Platform, Migration Toolkit for Containers, OpenShift Lightspeed, Hosted OpenShift Clusters, OpenShift Service Mesh, Red Hat Enterprise Linux AI, Red Hat OpenShift AI (RHOAI), and Red Hat Satellite. The flaw in aiohttp's parser logic could enable request smuggling if non-ASCII decimals are present in the HTTP Range header, potentially bypassing security controls or allowing unauthorized information access.

Меры по смягчению последствий

No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Containersrhmtc/openshift-migration-hook-runner-rhel8Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Fix deferred
OpenShift Service Mesh 2openshift-service-mesh/grafana-rhel8Fix deferred
OpenShift Service Mesh 2openshift-service-mesh/istio-cni-rhel8Fix deferred
OpenShift Service Mesh 2openshift-service-mesh/istio-must-gather-rhel9Fix deferred
OpenShift Service Mesh 2openshift-service-mesh/istio-operator-bundleFix deferred
OpenShift Service Mesh 2openshift-service-mesh/istio-rhel8-operatorFix deferred
OpenShift Service Mesh 2openshift-service-mesh/pilot-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=2427253aiohttp: aiohttp: Request smuggling vulnerability via non-ASCII decimals in Range header

EPSS

Процентиль: 14%
0.00045
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the Range header. There is no known impact, but there is the possibility that there's a method to exploit a request smuggling vulnerability. This issue is fixed in version 3.13.3.

CVSS3: 5.3
nvd
3 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the Range header. There is no known impact, but there is the possibility that there's a method to exploit a request smuggling vulnerability. This issue is fixed in version 3.13.3.

CVSS3: 5.3
debian
3 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

github
3 месяца назад

AIOHTTP has unicode match groups in regexes for ASCII protocol elements

suse-cvrf
24 дня назад

Security update for python-aiohttp

EPSS

Процентиль: 14%
0.00045
Низкий

5.4 Medium

CVSS3