Количество 12
Количество 12
GHSA-54jq-c3m8-4m76
AIOHTTP vulnerable to brute-force leak of internal static file path components
CVE-2025-69226
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.
CVE-2025-69226
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.
CVE-2025-69226
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.
CVE-2025-69226
AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...
ROS-20260420-80-0018
Уязвимость python-aiohttp
BDU:2026-07193
Уязвимость HTTP-клиента aiohttp, связанная с отсутствием защиты служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
ROS-20260420-73-0025
Уязвимость python-aiohttp
SUSE-SU-2026:0859-1
Security update for python-aiohttp
SUSE-SU-2026:0858-1
Security update for python-aiohttp
openSUSE-SU-2026:20204-1
Security update for python-aiohttp, python-Brotli
ALT-PU-2026-1250
ALT-PU-2026-1250: package `python3-module-aiohttp` update to version 3.13.3-alt0.p11.1
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-54jq-c3m8-4m76 AIOHTTP vulnerable to brute-force leak of internal static file path components | 0% Низкий | 9 месяцев назад | ||
CVE-2025-69226 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3. | CVSS3: 5.3 | 0% Низкий | 9 месяцев назад | |
CVE-2025-69226 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3. | CVSS3: 5.3 | 0% Низкий | 9 месяцев назад | |
CVE-2025-69226 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3. | CVSS3: 5.3 | 0% Низкий | 9 месяцев назад | |
CVE-2025-69226 AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ... | CVSS3: 5.3 | 0% Низкий | 9 месяцев назад | |
ROS-20260420-80-0018 Уязвимость python-aiohttp | CVSS3: 5.3 | 0% Низкий | 5 месяцев назад | |
BDU:2026-07193 Уязвимость HTTP-клиента aiohttp, связанная с отсутствием защиты служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 5.3 | 0% Низкий | 9 месяцев назад | |
ROS-20260420-73-0025 Уязвимость python-aiohttp | CVSS3: 5.3 | 0% Низкий | 5 месяцев назад | |
SUSE-SU-2026:0859-1 Security update for python-aiohttp | 7 месяцев назад | |||
SUSE-SU-2026:0858-1 Security update for python-aiohttp | 7 месяцев назад | |||
openSUSE-SU-2026:20204-1 Security update for python-aiohttp, python-Brotli | 8 месяцев назад | |||
ALT-PU-2026-1250 ALT-PU-2026-1250: package `python3-module-aiohttp` update to version 3.13.3-alt0.p11.1 | CVSS3: 7.5 | 8 месяцев назад |
Уязвимостей на страницу