VDB
CVE-2026-69243
CVE-2026-69243
PUBLISHED
CVSS 3.700000047683716 LOW
AIOHTTP: HTTP request smuggling via WebSocket upgrade
EPSS 0.27% · 19.6th percentile
Risk Scores
CVSS 3.1
3.700000047683716
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS Score
0.27%
19.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| aio-libs | aiohttp | < 3.14.2, < 3.14.2 |
| chainguard | kserve-models-web-app | 0, 0, 0 |
| chainguard | awx | 0 |
| chainguard | airflow-3 | 0, 0, 0 |
| chainguard | airflow-core-2 | 0, 0, 0 |
| wolfi | dask-kubernetes | 0, 0, 0 |
| chainguard | kserve | 0, 0, 0 |
| chainguard | open-webui | 0 |
| chainguard | apache-beam-python-3.11-sdk | 0, 0, 0 |
| chainguard | apache-beam-python-3.13-sdk | 0, 0, 0 |
| wolfi | kserve | 0, 0, 0 |
| wolfi | open-webui | 0, 0, 0 |
| chainguard | dask-kubernetes-fips | 0 |
| PyPI | aiohttp | 0 |
| chainguard | dask-kubernetes | 0, 0, 0 |
| chainguard | puppygraph-python | 0, 0, 0 |
| chainguard | tritonserver-backend-vllm-cuda-13.0 | 0, 0 |
| wolfi | airflow-3 | 0, 0, 0 |
| chainguard | text-generation-inference | 0, 0 |
| wolfi | py3-cassandra-medusa | 0, 0, 0 |
…and 5 more
Timeline
- Aug 3, 2026 CVE Published
- Aug 3, 2026 Coalition ESS Score
- Aug 4, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-69243 advisory
- https://github.com/advisories/GHSA-mfx4-hv73-q22v advisory
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mfx4-hv73-q22v url
- https://github.com/aio-libs/aiohttp/pull/13017 patch
- https://github.com/aio-libs/aiohttp/commit/6ae358f0983c3f4d6f67692b2f8e65dc8e091c98 patch
- https://github.com/aio-libs/aiohttp/releases/tag/v3.14.2 url