CVE-2025-69227High· 7.5▾ TwilightA flaw was found in aiohttp, an asynchronous HTTP client/server framework for Python. A remote attacker could exploit this vulnerability by sending a specially crafted POST request to an application using the Request.post() method, provide…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.3%
0.3% → 0.4%
— → 7.5
medium → high
7.5 → —
high → medium
— → 7.5
medium → high
Last analysed / modified upstream
A flaw was found in aiohttp, an asynchronous HTTP client/server framework for Python. A remote attacker could exploit this vulnerability by sending a specially crafted POST request to an application using the Request.post() method, provided that Python optimizations are enabled. This could lead to an infinite loop, resulting in a Denial of Service (DoS) attack, making the affected application unavailable.
aiohttp: aiohttp: Denial of Service via specially crafted POST request — rated Moderate by Red Hat. Released 2025-01-01, updated 2026-09-14.
Affected:
Fixed:
No fix planned:
Not affected:
For more information visit https://access.redhat.com/errata/RHSA-2026:6761 https://access.redhat.com/errata/RHSA-2026:6761 For more information visit https://access.redhat.com/errata/RHSA-2026:5809 https://access.redhat.com/errata/RHSA-2026:5809 For more information visit https://access.redhat.com/errata/RHSA-2026:6762 https://access.redhat.com/errata/RHSA-2026:6762
Workarounds / mitigations:
Affected packages:
aiohttp < 3.13.3Patched in:
aiohttp 3.13.3Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-30922High· 7.5pyasn1 Vulnerable to Denial of Service via Unbounded Recursion
CVE-2026-27628High· 7.5pypdf: possible infinite loop when loading circular /Prev entries in cross-reference streams (CVE-2026-27628)
CVE-2026-43871High· 7.5thrift: Apache Thrift: Denial of Service via infinite loop (CVE-2026-43871)
CVE-2026-76220High· 8.8gitpython: GitPython: Arbitrary command execution via crafted kwargs (CVE-2026-76220)
CVE-2026-76221High· 8.8gitpython: GitPython: Arbitrary code execution via config-name injection (CVE-2026-76221)
CVE-2026-76218High· 7.5gitpython: GitPython: Remote Code Execution via malicious Git hooks (CVE-2026-76218)