Description
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust the host's memory. This issue is fixed in version 3.13.3.
Published: 2026-01-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6141-1 python-aiohttp security update
Github GHSA Github GHSA GHSA-6mq8-rvhq-8wgg AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
Ubuntu USN Ubuntu USN USN-8032-1 AIOHTTP vulnerabilities
References
Link Providers
https://access.redhat.com/errata/RHSA-2026:10184 cve-icon
https://access.redhat.com/errata/RHSA-2026:1249 cve-icon
https://access.redhat.com/errata/RHSA-2026:1497 cve-icon
https://access.redhat.com/errata/RHSA-2026:1506 cve-icon
https://access.redhat.com/errata/RHSA-2026:1596 cve-icon
https://access.redhat.com/errata/RHSA-2026:1599 cve-icon
https://access.redhat.com/errata/RHSA-2026:1609 cve-icon
https://access.redhat.com/errata/RHSA-2026:19712 cve-icon
https://access.redhat.com/errata/RHSA-2026:2106 cve-icon
https://access.redhat.com/errata/RHSA-2026:2695 cve-icon
https://access.redhat.com/errata/RHSA-2026:3461 cve-icon
https://access.redhat.com/errata/RHSA-2026:3462 cve-icon
https://access.redhat.com/errata/RHSA-2026:3713 cve-icon
https://access.redhat.com/errata/RHSA-2026:37275 cve-icon
https://access.redhat.com/errata/RHSA-2026:3782 cve-icon
https://access.redhat.com/errata/RHSA-2026:3958 cve-icon
https://access.redhat.com/errata/RHSA-2026:3959 cve-icon
https://access.redhat.com/errata/RHSA-2026:3960 cve-icon
https://access.redhat.com/errata/RHSA-2026:41928 cve-icon
https://access.redhat.com/errata/RHSA-2026:59155 cve-icon
https://access.redhat.com/errata/RHSA-2026:59159 cve-icon
https://access.redhat.com/errata/RHSA-2026:6308 cve-icon
https://access.redhat.com/errata/RHSA-2026:6309 cve-icon
https://access.redhat.com/security/cve/CVE-2025-69223 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2427456 cve-icon
https://github.com/aio-libs/aiohttp/commit/2b920c39002cee0ec5b402581779bbaaf7c9138a cve-icon cve-icon cve-icon
https://github.com/aio-libs/aiohttp/security/advisories/GHSA-6mq8-rvhq-8wgg cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2025-69223 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69223.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2025-69223 cve-icon
History

Tue, 25 Aug 2026 13:30:00 +0000


Wed, 14 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:aiohttp:aiohttp:*:*:*:*:*:*:*:*

Wed, 07 Jan 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 06 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Jan 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Aio-libs
Aio-libs aiohttp Session
Aio-libs Project
Aio-libs Project aiohttp
Aiohttp
Aiohttp aio-libs
Aiohttp aiohttp
Vendors & Products Aio-libs
Aio-libs aiohttp Session
Aio-libs Project
Aio-libs Project aiohttp
Aiohttp
Aiohttp aio-libs
Aiohttp aiohttp

Mon, 05 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Description AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust the host's memory. This issue is fixed in version 3.13.3.
Title AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
Weaknesses CWE-409
CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Aio-libs Aiohttp Session
Aio-libs Project Aiohttp
Aiohttp Aio-libs Aiohttp
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-28T12:04:22.837Z

Reserved: 2025-12-29T20:45:58.699Z

Link: CVE-2025-69223

cve-icon Vulnrichment

Updated: 2026-08-26T12:05:05.402Z

cve-icon NVD

Status : Modified

Published: 2026-01-05T22:15:53.017

Modified: 2026-08-25T13:17:45.307

Link: CVE-2025-69223

cve-icon Redhat

Severity : Important

Publid Date: 2026-01-05T22:00:17Z

Links: CVE-2025-69223 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-01-06T14:16:25Z

Weaknesses