Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-69228

Опубликовано: 05 янв. 2026
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way that an AIOHTTP server's memory fills up uncontrollably during processing. If an application includes a handler that uses the Request.post() method, an attacker may be able to freeze the server by exhausting the memory. This issue is fixed in version 3.13.3.

A flaw was found in aiohttp. A remote attacker can craft a malicious request that, when processed by an aiohttp server using the Request.post() method, causes the server's memory to fill uncontrollably. This can lead to a Denial of Service (DoS) by freezing the server, making it unavailable to legitimate users.

Отчет

This vulnerability is rated Moderate for Red Hat products. A flaw in aiohttp allows a remote attacker to cause a Denial of Service (DoS) by sending a specially crafted POST request to an aiohttp server that utilizes the Request.post() method. This can lead to uncontrolled memory consumption, freezing the server and making the server unavailable.

Меры по смягчению последствий

No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Containersrhmtc/openshift-migration-hook-runner-rhel8Affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Affected
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Affected
OpenShift Service Mesh 2openshift-service-mesh/grafana-rhel8Affected
OpenShift Service Mesh 2openshift-service-mesh/istio-cni-rhel8Affected
OpenShift Service Mesh 2openshift-service-mesh/istio-must-gather-rhel9Affected
OpenShift Service Mesh 2openshift-service-mesh/istio-operator-bundleAffected
OpenShift Service Mesh 2openshift-service-mesh/istio-rhel8-operatorAffected
OpenShift Service Mesh 2openshift-service-mesh/pilot-rhel8Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2427254aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request

EPSS

Процентиль: 20%
0.00063
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way that an AIOHTTP server's memory fills up uncontrollably during processing. If an application includes a handler that uses the Request.post() method, an attacker may be able to freeze the server by exhausting the memory. This issue is fixed in version 3.13.3.

CVSS3: 7.5
nvd
3 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way that an AIOHTTP server's memory fills up uncontrollably during processing. If an application includes a handler that uses the Request.post() method, an attacker may be able to freeze the server by exhausting the memory. This issue is fixed in version 3.13.3.

CVSS3: 7.5
debian
3 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

github
3 месяца назад

AIOHTTP vulnerable to denial of service through large payloads

suse-cvrf
24 дня назад

Security update for python-aiohttp

EPSS

Процентиль: 20%
0.00063
Низкий

6.8 Medium

CVSS3