CVE-2025-69225

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the Range header. There is no known impact, but there is the possibility that there's a method to exploit a request smuggling vulnerability. This issue is fixed in version 3.13.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:aiohttp:aiohttp:*:*:*:*:*:*:*:*

History

14 Jan 2026, 19:13

Type Values Removed Values Added
First Time Aiohttp aiohttp
Aiohttp
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CPE cpe:2.3:a:aiohttp:aiohttp:*:*:*:*:*:*:*:*
References () https://github.com/aio-libs/aiohttp/commit/c7b7a044f88c71cefda95ec75cdcfaa4792b3b96 - () https://github.com/aio-libs/aiohttp/commit/c7b7a044f88c71cefda95ec75cdcfaa4792b3b96 - Patch
References () https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mqqc-3gqh-h2x8 - () https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mqqc-3gqh-h2x8 - Vendor Advisory, Patch

06 Jan 2026, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-06 00:15

Updated : 2026-01-14 19:13


NVD link : CVE-2025-69225

Mitre link : CVE-2025-69225

CVE.ORG link : CVE-2025-69225


JSON object : View

Products Affected

aiohttp

  • aiohttp
CWE
CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')