Логотип exploitDog
bind:CVE-2025-69226
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-69226

Количество 4

Количество 4

ubuntu логотип

CVE-2025-69226

10 дней назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.

EPSS: Низкий
nvd логотип

CVE-2025-69226

10 дней назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.

EPSS: Низкий
debian логотип

CVE-2025-69226

10 дней назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

EPSS: Низкий
github логотип

GHSA-54jq-c3m8-4m76

10 дней назад

AIOHTTP vulnerable to brute-force leak of internal static file path components

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-69226

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.

0%
Низкий
10 дней назад
nvd логотип
CVE-2025-69226

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.

0%
Низкий
10 дней назад
debian логотип
CVE-2025-69226

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

0%
Низкий
10 дней назад
github логотип
GHSA-54jq-c3m8-4m76

AIOHTTP vulnerable to brute-force leak of internal static file path components

0%
Низкий
10 дней назад

Уязвимостей на страницу