CVE-2025-69230
EUVD-2026-104206.01.2026, 00:15
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can lead to a logging storm. If the cookies attribute is accessed in an application, then an attacker may be able to trigger a storm of warning-level logs using a specially crafted Cookie header. This issue is fixed in 3.13.3.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| aiohttp | aiohttp | 𝑥 < 3.13.3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration