Логотип exploitDog
bind:"GHSA-54jq-c3m8-4m76" OR bind:"CVE-2025-69226"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-54jq-c3m8-4m76" OR bind:"CVE-2025-69226"

Количество 8

Количество 8

github логотип

GHSA-54jq-c3m8-4m76

3 месяца назад

AIOHTTP vulnerable to brute-force leak of internal static file path components

EPSS: Низкий
ubuntu логотип

CVE-2025-69226

3 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2025-69226

3 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-69226

3 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2025-69226

3 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0859-1

24 дня назад

Security update for python-aiohttp

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0858-1

24 дня назад

Security update for python-aiohttp

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20204-1

около 2 месяцев назад

Security update for python-aiohttp, python-Brotli

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-54jq-c3m8-4m76

AIOHTTP vulnerable to brute-force leak of internal static file path components

0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2025-69226

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.

CVSS3: 5.3
0%
Низкий
3 месяца назад
redhat логотип
CVE-2025-69226

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.

CVSS3: 5.3
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-69226

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.

CVSS3: 5.3
0%
Низкий
3 месяца назад
debian логотип
CVE-2025-69226

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

CVSS3: 5.3
0%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:0859-1

Security update for python-aiohttp

24 дня назад
suse-cvrf логотип
SUSE-SU-2026:0858-1

Security update for python-aiohttp

24 дня назад
suse-cvrf логотип
openSUSE-SU-2026:20204-1

Security update for python-aiohttp, python-Brotli

около 2 месяцев назад

Уязвимостей на страницу