{"id":"CVE-2026-69244","title":"AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python","summary":"AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response. An attacker contro…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-125","CWE-400","CWE-416"],"vendor":"Red Hat","product":"Red Hat OpenShift AI 2.25","affected":["exploit_intelligence","lightspeed_core","migration_toolkit_for_applications 8","openshift_lightspeed","ai_inference_server","ansible_automation_platform 2","enterprise_linux_ai_rhel_ai 3","openshift_ai_rhoai","satellite 6","update_infrastructure_4_for_cloud_providers","update_infrastructure 5","ansible_automation_platform_2_5_for_rhel 8","satellite_6_16_for_rhel 8","ansible_automation_platform_2_5_for_rhel 9","ansible_automation_platform_2_6_for_rhel 9","satellite_6_16_for_rhel 9","satellite_6_17_for_rhel 9","satellite_6_18_for_rhel 9","satellite_6_19_for_rhel 9","ansible_automation_platform 2.5","ansible_automation_platform 2.6","ansible_automation_platform 2.7","ansible_automation_platform_execution_environments 2.18","discovery 2","openshift_ai 2.25","openshift_ai 3.4","satellite 6.18","satellite 6.19"],"patched":["ansible_automation_platform_2_5_for_rhel 8","satellite_6_16_for_rhel 8","ansible_automation_platform_2_5_for_rhel 9","ansible_automation_platform_2_6_for_rhel 9","satellite_6_16_for_rhel 9","satellite_6_17_for_rhel 9","satellite_6_18_for_rhel 9","satellite_6_19_for_rhel 9","ansible_automation_platform 2.5","ansible_automation_platform 2.6","ansible_automation_platform 2.7","ansible_automation_platform_execution_environments 2.18","discovery 2","openshift_ai 2.25","openshift_ai 3.4","satellite 6.18","satellite 6.19"],"published":"2026-08-03","updated":"2026-09-10","sourceUpdated":"2026-09-10T20:36:14.340","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-69244","references":[{"url":"https://github.com/aio-libs/aiohttp/commit/49f65d54150397892f7bcc4aae887767d51c322d","label":"security-advisories@github.com"},{"url":"https://github.com/aio-libs/aiohttp/pull/13223","label":"security-advisories@github.com"},{"url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.14.3","label":"security-advisories@github.com"},{"url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-cq5v-8q36-5273","label":"security-advisories@github.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-69244.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-69244"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2510825"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-69244"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69244"},{"url":"https://access.redhat.com/errata/RHSA-2026:59135"},{"url":"https://access.redhat.com/errata/RHSA-2026:63327"},{"url":"https://access.redhat.com/errata/RHSA-2026:59136"},{"url":"https://access.redhat.com/errata/RHSA-2026:63387"},{"url":"https://access.redhat.com/errata/RHSA-2026:63386"},{"url":"https://access.redhat.com/errata/RHSA-2026:63385"},{"url":"https://access.redhat.com/errata/RHSA-2026:59159"},{"url":"https://access.redhat.com/errata/RHSA-2026:59155"},{"url":"https://access.redhat.com/errata/RHSA-2026:59153"},{"url":"https://access.redhat.com/errata/RHSA-2026:55853"},{"url":"https://access.redhat.com/errata/RHSA-2026:55852"},{"url":"https://access.redhat.com/errata/RHSA-2026:54760"},{"url":"https://access.redhat.com/errata/RHSA-2026:65126"},{"url":"https://access.redhat.com/errata/RHSA-2026:60520"},{"url":"https://access.redhat.com/errata/RHSA-2026:63334"},{"url":"https://access.redhat.com/errata/RHSA-2026:63337"},{"url":"https://github.com/advisories/GHSA-cq5v-8q36-5273"},{"url":"https://github.com/aio-libs/aiohttp"},{"url":"https://access.redhat.com/errata/RHSA-2026:68696"},{"url":"https://access.redhat.com/errata/RHSA-2026:68699"},{"url":"https://access.redhat.com/errata/RHSA-2026:68698"},{"url":"https://access.redhat.com/errata/RHSA-2026:68697"},{"url":"https://access.redhat.com/errata/RHSA-2026:67279"},{"url":"https://access.redhat.com/errata/RHSA-2026:68770"},{"url":"https://access.redhat.com/errata/RHSA-2026:69539"},{"url":"https://access.redhat.com/errata/RHSA-2026:70965"},{"url":"https://access.redhat.com/errata/RHSA-2026:70979"},{"url":"https://access.redhat.com/errata/RHSA-2026:70995"},{"url":"https://access.redhat.com/errata/RHSA-2026:70969"},{"url":"https://access.redhat.com/errata/RHSA-2026:71179"}],"tags":["nvd","csaf","vex","red-hat","ghsa","pip","osv"],"epss":0.003,"epssPercentile":0.22855,"aliases":["GHSA-cq5v-8q36-5273","PYSEC-2026-3545"],"ecosystem":"pip","cvssSource":"vendor","ingestedAt":"2026-08-03T21:30:01.541Z","slug":"CVE-2026-69244","body":"## Overview\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response. An attacker controlled server, or possibly an accidental response, could trigger a DoS in the client. The vulnerable path was error message construction in aiohttp/_http_parser.pyx, where an llhttp error-position pointer was used to build a snippet for malformed chunked responses and malformed request or response bytes at the buffer end. This issue is fixed in version 3.14.3.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-69244)\n\nAffected packages:\n\n- `aiohttp <= 3.14.2`\n\nPatched in:\n\n- `aiohttp 3.14.3`\n\nSource: https://github.com/advisories/GHSA-cq5v-8q36-5273\n\n## Vendor advisories\n\n- **RHSA-2026:59135** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59135)\n- **RHSA-2026:63327** · Red Hat · fixed in: Red Hat Satellite 6.16 for RHEL 8, Red Hat Satellite 6.16 for RHEL 9 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63327)\n- **RHSA-2026:59136** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59136)\n- **RHSA-2026:63387** · Red Hat · fixed in: Red Hat Satellite 6.17 for RHEL 9 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63387)\n- **RHSA-2026:63386** · Red Hat · fixed in: Red Hat Satellite 6.18 for RHEL 9 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63386)\n- **RHSA-2026:63385** · Red Hat · fixed in: Red Hat Satellite 6.19 for RHEL 9 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63385)\n- **RHSA-2026:59159** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59159)\n- **RHSA-2026:59155** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59155)\n- **RHSA-2026:59153** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59153)\n- **RHSA-2026:55853** · Red Hat · fixed in: Red Hat Ansible Automation Platform Execution Environments 2.18 · released 2026-08-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:55853)\n- **RHSA-2026:55852** · Red Hat · fixed in: Red Hat Ansible Automation Platform Execution Environments 2.18 · released 2026-08-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:55852)\n- **Red Hat VEX** · Important · affected: Exploit Intelligence, Lightspeed Core, Migration Toolkit for Applications 8, OpenShift Lightspeed, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, … · no fix planned: Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Update Infrastructure 4 for Cloud Providers, Red Hat Update Infrastructure 5, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-69244.json)\n- **RHSA-2026:68696** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68696)\n- **RHSA-2026:68699** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68699)\n- **RHSA-2026:68698** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68698)\n- **RHSA-2026:68697** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68697)\n- **RHSA-2026:70965** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70965)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":5442,"id":"CVE-2026-69244","ts":1788887282702,"field":"cvss","old":null,"new":"7.5"},{"seq":4325,"id":"CVE-2026-69244","ts":1788886396427,"field":"cvss","old":"7.5","new":null},{"seq":3145,"id":"CVE-2026-69244","ts":1788883132940,"field":"cvss","old":null,"new":"7.5"}]}