aiohttp是aio-libs开源的一个开源的用于 asyncio 和 Python 的异步 HTTP 客户端/服务器框架。 aiohttp 3.13.2及之前版本存在信息泄露漏洞,该漏洞源于路径规范化逻辑可能泄露绝对路径组件信息,可能导致路径遍历攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-69223 | 7.5 HIGH | AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb |
| CVE-2025-69230 | AIOHTTP Vulnerable to Cookie Parser Warning Storm | |
| CVE-2025-69227 | AIOHTTP vulnerable to DoS when bypassing asserts | |
| CVE-2025-69229 | AIOHTTP vulnerable to DoS through chunked messages | |
| CVE-2025-69225 | AIOHTTP Regex Mismatch Allows Unicode in ASCII-Only Protocol Fields | |
| CVE-2025-69224 | AIOHTTP's Unicode processing of header values could cause parsing discrepancies | |
| CVE-2025-69228 | AIOHTTP vulnerable to denial of service through large payloads |
No comments yet