CVE-2026-69244
Reported by GitHub_M · Published August 3, 2026
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response. An attacker controlled server, or possibly an accidental response, could trigger a DoS in the client. The vulnerable path was error message construction in aiohttp/_http_parser.pyx, where an llhttp error-position pointer was used to build a snippet for malformed chunked responses and malformed request or response bytes at the buffer end. This issue is fixed in version 3.14.3.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| aio-libs | aiohttp | < 3.14.3 |
| chainguard | dask-kubernetes | 0, 0, 0 |
| PyPI | aiohttp | 0 |
| chainguard | airflow-core-2 | 0, 0, 0 |
| chainguard | vllm-cuda-13.2 | 0, 0, 0 |
| chainguard | apache-beam-python-3.11-sdk | 0, 0, 0 |
| aio-libs | aiohttp | < 3.14.3, < 3.14.3, < 3.14.3 |
| chainguard | awx | 0, 0, 0 |
| wolfi | open-webui | 0, 0, 0 |
| wolfi | dask-kubernetes | 0, 0, 0 |
| wolfi | py3-cassandra-medusa | 0, 0, 0 |
| chainguard | apache-beam-python-3.12-sdk | 0, 0, 0 |
| chainguard | dask-kubernetes-fips | 0, 0, 0 |
| chainguard | puppygraph-python | 0, 0, 0 |
| chainguard | lmcache-cuda-12.8 | 0, 0, 0 |
| chainguard | py3-cassandra-medusa | 0, 0, 0 |
| chainguard | text-generation-inference | 0, 0, 0 |
| chainguard | apache-beam-python-3.13-sdk | 0, 0, 0 |
| chainguard | tritonserver-backend-vllm-cuda-13.0 | 0, 0, 0 |
| chainguard | py3.13-scanner-test-libraries-aiohttp | 0, 0, 0 |
…and 8 more
Timeline
- Aug 3, 2026 CVE Published
- Aug 3, 2026 Coalition ESS Score
- Aug 4, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Aug 25, 2026 Distribution Patch
- Aug 25, 2026 Security Advisory
- Aug 25, 2026 Distribution Patch
- Aug 25, 2026 Security Advisory
- Aug 29, 2026 EPSS Score
- Sep 4, 2026 EPSS Score
- Sep 4, 2026 Distribution Patch
References
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-cq5v-8q36-5273 x_refsource_CONFIRM
- https://github.com/aio-libs/aiohttp/pull/13223 x_refsource_MISC
- https://github.com/aio-libs/aiohttp/commit/49f65d54150397892f7bcc4aae887767d51c322d x_refsource_MISC
- https://github.com/aio-libs/aiohttp/releases/tag/v3.14.3 x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2026-69244 advisory
- https://github.com/advisories/GHSA-cq5v-8q36-5273 advisory