VDB

ESB-2026.5961

ESB-2026.5961 PUBLISHED CVSS 9.100000381469727 CRITICAL

=========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2026.5961 python-aiohttp security update 2 June 2026 =========================================================================== AUSCERT Security Bulletin Summary --------------------------------- Product: python-aiohttp Publisher: Debian Operating System: Debian GNU/Linux Resolution: Patch/Upgrade CVE Names: CVE-2026-34513 CVE-2026-34514 CVE-2026-34516 CVE-2026-34517 CVE-2026-34518 CVE-2026-34519 CVE-2026-34520 CVE-2026-34525 CVE-2025-69224 CVE-2025-69225 CVE-2025-69226 CVE-2025-69227 CVE-2025-69228 CVE-2025-69229 CVE-2025-53643 CVE-2026-22815 Original Bulletin: https://lists.debian.org/debian-lts-announce/2026/06/msg00002.html Comment: CVSS (Max): 9.1 CVE-2026-34520 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H) CVSS Source: NIST, [CISA-ADP] Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H EPSS (Max): 0.3% (56th) CVE-2025-53643 2026-05-31 - --------------------------BEGIN INCLUDED TEXT-------------------- ------------------------------------------------------------------------- Debian LTS Advisory DLA-4613-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Daniel Leidert June 01, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : python-aiohttp Version : 3.7.4-1+deb11u2 CVE ID : CVE-2025-53643 CVE-2025-69224 CVE-2025-69225 CVE-2025-69226 CVE-2025-69227 CVE-2025-69228 CVE-2025-69229 CVE-2026-22815 CVE-2026-34513 CVE-2026-34514 CVE-2026-34516 CVE-2026-34517 CVE-2026-34518 CVE-2026-34519 CVE-2026-34520 CVE-2026-34525 Several vulnerabilities have been found in aiohttp, an asynchronous HTTP client/server framework for asyncio and Python. CVE-2025-53643 Request smuggling vulnerability due to not parsing trailer sections of an HTTP request. CVE-2025-69224 Possible request smuggling attack in the HTTP parser with the presence of non-ASCII characters. CVE-2025-69225 Parser logic which allows non-ASCII decimals to be present in the Range header. CVE-2025-69226 Path traversal vulnerability that allows an attacker to ascertain the existence of path components. CVE-2025-69227 When processing a POST body, an infinite loop can occur when assert statements are bypassed leading to a possible DoS attack. CVE-2025-69228 Possible DoS attack that can freeze the server by exhausting the memory using Request.post(). CVE-2025-69229 The handling of chunked messages that can result in an excessive blocking of CPU usage when receiving a large number of chunks. CVE-2026-22815 Uncapped memory usage due to insufficient restrictions in header and trailer handling. CVE-2026-34513 Excessive memory usage possibly resulting in a DoS due to an an unbounded DNS cache. CVE-2026-34514 Header injection. CVE-2026-34516 Potential DoS vulnerability caused by a response with an excessive number of multipart headers. CVE-2026-34517 Possible excessive memory usage caused by some multipart form fields due to reading the entiry field into memory before checking client_max_size. CVE-2026-34518 Leaking sensitive information by dropping the Cookie and the Proxy- Authorization headers When following redirects to a different origin. CVE-2026-34519 Header injection via the reason parameter. CVE-2026-34520 Possible security bypass by checking header values for control characters accordingly to RFC 9110. CVE-2026-34525 Headers can be duplicated, e.g. the host header. For Debian 11 bullseye, these problems have been fixed in version 3.7.4-1+deb11u2. We recommend that you upgrade your python-aiohttp packages. For the detailed security status of python-aiohttp please refer to its security tracker page at: https://security-tracker.debian.org/tracker/python-aiohttp Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS - --------------------------END INCLUDED TEXT---------------------- You have received this e-mail bulletin as a result of your organisation's registration with AUSCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AUSCERT's members. As AUSCERT did not write the document quoted above, AUSCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AUSCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://portal.auscert.org.au/bulletins/ =========================================================================== AUSCERT The University of Queensland, Brisbane QLD 4072 Australia e: auscert@auscert.org.au t: +61 (0)7 3365 4417 Allies in Cyber Security ===========================================================================

Risk Scores

CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Affected Products

VendorProductVersions
Debianpython-aiohttp

Timeline

  • Jun 1, 2026 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›