Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-69229

Опубликовано: 05 янв. 2026
Источник: redhat
CVSS3: 5.8
EPSS Низкий

Описание

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling of chunked messages can result in excessive blocking CPU usage when receiving a large number of chunks. If an application makes use of the request.read() method in an endpoint, it may be possible for an attacker to cause the server to spend a moderate amount of blocking CPU time (e.g. 1 second) while processing the request. This could potentially lead to DoS as the server would be unable to handle other requests during that time. This issue is fixed in version 3.13.3.

A flaw was found in aiohttp, an asynchronous HTTP client/server framework for asyncio and Python. An attacker can exploit this vulnerability by sending a large number of chunks in a message. This can lead to excessive blocking CPU usage when the application processes the request, potentially causing a Denial of Service (DoS) as the server becomes unresponsive to other requests.

Отчет

This vulnerability is rated Moderate for Red Hat products. A flaw in the aiohttp library, used across various Red Hat offerings, allows an unauthenticated attacker to cause a Denial of Service. By sending a large number of chunks in an HTTP message, an attacker can trigger excessive CPU usage, rendering the affected service temporarily unresponsive.

Меры по смягчению последствий

No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Containersrhmtc/openshift-migration-hook-runner-rhel8Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Fix deferred
OpenShift Service Mesh 2openshift-service-mesh/grafana-rhel8Fix deferred
OpenShift Service Mesh 2openshift-service-mesh/istio-cni-rhel8Fix deferred
OpenShift Service Mesh 2openshift-service-mesh/istio-must-gather-rhel9Fix deferred
OpenShift Service Mesh 2openshift-service-mesh/istio-operator-bundleFix deferred
OpenShift Service Mesh 2openshift-service-mesh/istio-rhel8-operatorFix deferred
OpenShift Service Mesh 2openshift-service-mesh/pilot-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2427257aiohttp: AIOHTTP: Denial of Service via excessive CPU usage in chunked message handling

EPSS

Процентиль: 16%
0.00052
Низкий

5.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling of chunked messages can result in excessive blocking CPU usage when receiving a large number of chunks. If an application makes use of the request.read() method in an endpoint, it may be possible for an attacker to cause the server to spend a moderate amount of blocking CPU time (e.g. 1 second) while processing the request. This could potentially lead to DoS as the server would be unable to handle other requests during that time. This issue is fixed in version 3.13.3.

CVSS3: 5.3
nvd
3 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling of chunked messages can result in excessive blocking CPU usage when receiving a large number of chunks. If an application makes use of the request.read() method in an endpoint, it may be possible for an attacker to cause the server to spend a moderate amount of blocking CPU time (e.g. 1 second) while processing the request. This could potentially lead to DoS as the server would be unable to handle other requests during that time. This issue is fixed in version 3.13.3.

CVSS3: 5.3
debian
3 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

github
3 месяца назад

AIOHTTP vulnerable to DoS through chunked messages

suse-cvrf
24 дня назад

Security update for python-aiohttp

EPSS

Процентиль: 16%
0.00052
Низкий

5.8 Medium

CVSS3