VYPR
Unrated severityOSV Advisory· Published Aug 4, 2026

Debian python-aiohttp: AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. …

CVE-2026-69243

Description

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were vulnerable to a request smuggling attack relating to WebSocket upgrades. If using the server-side component, an attacker may be able to execute a request smuggling vulnerability using an edge case in the WebSocket upgrade procedure. A WebSocket upgrade request with a body could cause the parser to switch protocols before the complete request body was received, leaving trailing bytes to be handled as upgraded-protocol or pipelined data rather than normal HTTP body data. This issue is fixed in version 3.14.2.

Affected products

3
  • Aio Libs/AiohttpOSV2 versions
    v3.14.1, v3.14.0, v3.13.0, …+ 1 more
    • (no CPE)range: v3.14.1, v3.14.0, v3.13.0, …
    • (no CPE)range: <3.14.2
  • Range: <3.14.2

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.