CVE-2025-69228 - CVE House
Back to Database
Status published Medium CVE-2025-69228

AIOHTTP vulnerable to denial of service through large payloads

Vulnerability Description

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way that an AIOHTTP server's memory fills up uncontrollably during processing. If an application includes a handler that uses the Request.post() method, an attacker may be able to freeze the server by exhausting the memory. This issue is fixed in version 3.13.3.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-69228

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

aiohttp
Vulnerable Versions:
< 3.13.3

Timeline

Official Publish: January 5th, 2026
Last Modified: January 6th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)