Logo
vulnerabilityCVE-2025-69228
Name
CVE-2025-69228
Source
NVD ( link)Debian ( link)
Description
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way that an AIOHTTP server's memory fills up uncontrollably during processing. If an application includes a handler that uses the Request.post() method, an attacker may be able to freeze the server by exhausting the memory. This issue is fixed in version 3.13.3.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
python3-aiohttp
Patched

Vulnerability Ratings#


6.6
CVSSv4
7.5
CVSSv31
NaN
other

Others affected component#


Name
Project
Project Version
Version
Status
yocto
kirkstone
3.8.6
Not Affected

Resolved with patches#


python3-aiohttp (yocto:scarthgap)

#
Title
Author
Resolve
1
Enforce client_max_size over entire multipart form (#11889)
Gyorgy Sarvari <skandigraun@gmail.com>
CVE-2025-69228