Логотип exploitDog
bind:CVE-2025-69226
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-69226

Количество 4

Количество 4

ubuntu логотип

CVE-2025-69226

около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-69226

около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2025-69226

около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-54jq-c3m8-4m76

около 1 месяца назад

AIOHTTP vulnerable to brute-force leak of internal static file path components

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-69226

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2025-69226

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2025-69226

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-54jq-c3m8-4m76

AIOHTTP vulnerable to brute-force leak of internal static file path components

0%
Низкий
около 1 месяца назад

Уязвимостей на страницу