Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 10

Количество 10

github логотип

GHSA-54jq-c3m8-4m76

7 месяцев назад

AIOHTTP vulnerable to brute-force leak of internal static file path components

EPSS: Низкий
ubuntu логотип

CVE-2025-69226

7 месяцев назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2025-69226

7 месяцев назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-69226

7 месяцев назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2025-69226

7 месяцев назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2026-07193

7 месяцев назад

Уязвимость HTTP-клиента aiohttp, связанная с отсутствием защиты служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20260420-73-0025

4 месяца назад

Уязвимость python-aiohttp

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0859-1

5 месяцев назад

Security update for python-aiohttp

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0858-1

5 месяцев назад

Security update for python-aiohttp

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20204-1

6 месяцев назад

Security update for python-aiohttp, python-Brotli

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-54jq-c3m8-4m76

AIOHTTP vulnerable to brute-force leak of internal static file path components

0%
Низкий
7 месяцев назад
ubuntu логотип
CVE-2025-69226

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.

CVSS3: 5.3
0%
Низкий
7 месяцев назад
redhat логотип
CVE-2025-69226

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.

CVSS3: 5.3
0%
Низкий
7 месяцев назад
nvd логотип
CVE-2025-69226

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.

CVSS3: 5.3
0%
Низкий
7 месяцев назад
debian логотип
CVE-2025-69226

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

CVSS3: 5.3
0%
Низкий
7 месяцев назад
fstec логотип
BDU:2026-07193

Уязвимость HTTP-клиента aiohttp, связанная с отсутствием защиты служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.3
0%
Низкий
7 месяцев назад
redos логотип
ROS-20260420-73-0025

Уязвимость python-aiohttp

CVSS3: 5.3
0%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:0859-1

Security update for python-aiohttp

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0858-1

Security update for python-aiohttp

5 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20204-1

Security update for python-aiohttp, python-Brotli

6 месяцев назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.