CVE-2025-69228Medium· 6.8▾ SunlitA flaw was found in aiohttp. A remote attacker can craft a malicious request that, when processed by an aiohttp server using the `Request.post()` method, causes the server's memory to fill uncontrollably. This can lead to a Denial of Servi…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.3%
0.3% → 0.4%
— → 6.8
6.8 → —
— → 6.8
Last analysed / modified upstream
A flaw was found in aiohttp. A remote attacker can craft a malicious request that, when processed by an aiohttp server using the Request.post() method, causes the server's memory to fill uncontrollably. This can lead to a Denial of Service (DoS) by freezing the server, making it unavailable to legitimate users.
aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request — rated Moderate by Red Hat. Released 2025-01-01, updated 2026-09-14.
Affected:
Fixed:
No fix planned:
Not affected:
For more information visit https://access.redhat.com/errata/RHSA-2026:6761 https://access.redhat.com/errata/RHSA-2026:6761 For more information visit https://access.redhat.com/errata/RHSA-2026:5809 https://access.redhat.com/errata/RHSA-2026:5809 For more information visit https://access.redhat.com/errata/RHSA-2026:6762 https://access.redhat.com/errata/RHSA-2026:6762
Workarounds / mitigations:
Affected packages:
aiohttp < 3.13.3Patched in:
aiohttp 3.13.3Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-67325High· 8.8GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature
CVE-2026-49855High· 7.5tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory consumption (CVE-2026-49855)
CVE-2026-78679Medium· 6.5GitPython: GitPython: Arbitrary file read via TagReference.create() (CVE-2026-78679)
CVE-2026-78678Medium· 6.5gitpython: GitPython: Arbitrary file read via Repo.blame() (CVE-2026-78678)
CVE-2026-78676Critical· 9.8gitpython: GitPython before 3.1.59 Remote Code Execution via Config Injection (CVE-2026-78676)
CVE-2026-78675Medium· 5.5GitPython: GitPython: Local file content disclosure via malicious .gitmodules (CVE-2026-78675)