AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow for an infinite loop to occur when assert statements are bypassed, resulting in a DoS attack when processing a POST body. If optimizations are enabled (-O or PYTHONOPTIMIZE=1), and the application includes a handler that uses the Request.post() method, then an attacker may be able to execute a DoS attack with a specially crafted message. This issue is fixed in version 3.13.3.
CVSS Details
- CVSS 4.0 Base Score: 6.6 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py3-aiohttp | Jan 13, 2026 | Jan 5, 2026 |
| Debian | — | Upgrade python-aiohttp | Jun 2, 2026 | Jun 2, 2026 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.3.10Upgrade Splunk Enterprise to version 10.2.1Upgrade Splunk Enterprise to version 10.0.4Upgrade Splunk Enterprise to version 9.4.9 | Jul 30, 2026 | Jan 5, 2026 |
| Ubuntu | — | Upgrade python3-aiohttp (Ubuntu Pro)Upgrade python3-aiohttp | Feb 17, 2026 | Jan 6, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub