AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust the host's memory. This issue is fixed in version 3.13.3.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py3-aiohttp | Jan 13, 2026 | Jan 5, 2026 |
| Debian | — | Upgrade python-aiohttp | Jul 23, 2026 | Jul 23, 2026 |
| Splunk | — | Upgrade Splunk Enterprise to version 10.0.4Upgrade Splunk Enterprise to version 10.2.1Upgrade Splunk Enterprise to version 9.3.10Upgrade Splunk Enterprise to version 9.4.9 | Jul 30, 2026 | Jan 5, 2026 |
| Ubuntu | — | Upgrade python3-aiohttpUpgrade python3-aiohttp (Ubuntu Pro) | Feb 17, 2026 | Jan 5, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub