Ad

CVE-2025-69223

HIGH CVSS 3.1: 7.5 EPSS 0.06%
Updated Jan 14, 2026
Aiohttp
Parameter Value
CVSS 7.5 (HIGH)
Affected Versions before 3.13.3
Fixed In 3.13.3
Type CWE-409, CWE-770 (Allocation Without Limits)
Vendor Aiohttp
Public PoC No

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust the host's memory.

This issue is fixed in version 3.13.3.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Aiohttp Aiohttp
cpe:2.3:a:aiohttp:aiohttp:*:*:*:*:*:*:*:*
3.13.3