Description
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust the host's memory. This issue is fixed in version 3.13.3.
Published: 2026-01-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6141-1 python-aiohttp security update
Github GHSA Github GHSA GHSA-6mq8-rvhq-8wgg AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
History

Wed, 14 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:aiohttp:aiohttp:*:*:*:*:*:*:*:*

Wed, 07 Jan 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 06 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Jan 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Aio-libs
Aio-libs aiohttp Session
Aio-libs Project
Aio-libs Project aiohttp
Aiohttp
Aiohttp aio-libs
Aiohttp aiohttp
Vendors & Products Aio-libs
Aio-libs aiohttp Session
Aio-libs Project
Aio-libs Project aiohttp
Aiohttp
Aiohttp aio-libs
Aiohttp aiohttp

Mon, 05 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Description AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust the host's memory. This issue is fixed in version 3.13.3.
Title AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
Weaknesses CWE-409
CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Aio-libs Aiohttp Session
Aio-libs Project Aiohttp
Aiohttp Aio-libs Aiohttp
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-01-06T19:04:01.249Z

Reserved: 2025-12-29T20:45:58.699Z

Link: CVE-2025-69223

cve-icon Vulnrichment

Updated: 2026-01-06T14:26:19.595Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-05T22:15:53.017

Modified: 2026-01-14T19:11:07.500

Link: CVE-2025-69223

cve-icon Redhat

Severity : Important

Publid Date: 2026-01-05T22:00:17Z

Links: CVE-2025-69223 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-01-06T14:16:25Z

Weaknesses