VDB
CVE-2026-69244
CVE-2026-69244
PUBLISHED
CVSS 6.5 MEDIUM
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
EPSS 0.30% · 22.2th percentile
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
0.30%
22.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| chainguard | dask-kubernetes | 0, 0, 0 |
| PyPI | aiohttp | 0 |
| chainguard | airflow-core-2 | 0, 0, 0 |
| chainguard | vllm-cuda-13.2 | 0 |
| chainguard | apache-beam-python-3.11-sdk | 0, 0, 0 |
| aio-libs | aiohttp | < 3.14.3, < 3.14.3 |
| chainguard | awx | 0 |
| wolfi | open-webui | 0, 0, 0 |
| wolfi | dask-kubernetes | 0, 0, 0 |
| wolfi | py3-cassandra-medusa | 0, 0, 0 |
| chainguard | apache-beam-python-3.12-sdk | 0, 0, 0 |
| chainguard | dask-kubernetes-fips | 0, 0 |
| chainguard | puppygraph-python | 0, 0, 0 |
| chainguard | lmcache-cuda-12.8 | 0 |
| chainguard | py3-cassandra-medusa | 0, 0, 0 |
| chainguard | text-generation-inference | 0, 0 |
| chainguard | apache-beam-python-3.13-sdk | 0, 0, 0 |
| chainguard | tritonserver-backend-vllm-cuda-13.0 | 0, 0 |
| chainguard | py3.13-scanner-test-libraries-aiohttp | 0, 0, 0 |
| wolfi | kserve | 0, 0, 0 |
…and 6 more
Timeline
- Aug 3, 2026 CVE Published
- Aug 3, 2026 Coalition ESS Score
- Aug 4, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-69244 advisory
- https://github.com/advisories/GHSA-cq5v-8q36-5273 advisory
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-cq5v-8q36-5273 url
- https://github.com/aio-libs/aiohttp/pull/13223 patch
- https://github.com/aio-libs/aiohttp/commit/49f65d54150397892f7bcc4aae887767d51c322d patch
- https://github.com/aio-libs/aiohttp/releases/tag/v3.14.3 url