Security Advisory

CVE-2025-69228

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-01-05 23:30:33
Last updated 2026-01-06 19:02:29
Assigner GitHub_M
State PUBLISHED

Description

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way that an AIOHTTP servers memory fills up uncontrollably during processing. If an application includes a handler that uses the Request.post() method, an attacker may be able to freeze the server by exhausting the memory. This issue is fixed in version 3.13.3.