Unrated severityOSV Advisory· Published Aug 4, 2026
Debian python-aiohttp: AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. …
CVE-2026-69244
Description
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response. An attacker controlled server, or possibly an accidental response, could trigger a DoS in the client. The vulnerable path was error message construction in aiohttp/_http_parser.pyx, where an llhttp error-position pointer was used to build a snippet for malformed chunked responses and malformed request or response bytes at the buffer end. This issue is fixed in version 3.14.3.
Affected products
2Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.