Logo
vulnerabilityCVE-2025-53643
Name
CVE-2025-53643
Source
NVD ( link)Debian ( link)
Description
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability due to not parsing trailer sections of an HTTP request. If a pure Python version of aiohttp is installed (i.e. without the usual C extensions) or AIOHTTP_NO_EXTENSIONS is enabled, then an attacker may be able to execute a request smuggling attack to bypass certain firewalls or proxy protections. Version 3.12.14 contains a patch for this issue.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
python3-aiohttp
Patched

Vulnerability Ratings#


1.7
CVSSv4
7.5
CVSSv31
NaN
other

Others affected component#


Name
Project
Project Version
Version
Status
yocto
kirkstone
3.8.6
Patched

Resolved with patches#


python3-aiohttp (yocto:kirkstone)

#
Title
Author
Resolve
1
Add trailer parsing logic (#11269) (#11287)
Sam Bull <git@sambull.org>
CVE-2025-53643

python3-aiohttp (yocto:scarthgap)

#
Title
Author
Resolve
1
Add trailer parsing logic (#11269) (#11287)
Sam Bull <git@sambull.org>
CVE-2025-53643