CVE-2025-69223

HIGH

aiohttp < 3.13.3 - Denial of Service via Zip Bomb Decompression

Title source: llm
STIX 2.1

Description

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust the host's memory. This issue is fixed in version 3.13.3.

References (26)

Core 26
Core References

Scores

CVSS v3 7.5
EPSS 0.0050
EPSS Percentile 40.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-409 CWE-770
Status published
Products (3)
aio-libs/aiohttp < 3.13.3
aiohttp/aiohttp < 3.13.3
pypi/aiohttp 0 - 3.13.3PyPI
Published Jan 05, 2026
Tracked Since Feb 18, 2026