Vulnerability Description
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the Range header. There is no known impact, but there is the possibility that there's a method to exploit a request smuggling vulnerability. This issue is fixed in version 3.13.3.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aiohttp | Aiohttp | < 3.13.3 |
Related Weaknesses (CWE)
References
- https://github.com/aio-libs/aiohttp/commit/c7b7a044f88c71cefda95ec75cdcfaa4792b3Patch
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mqqc-3gqh-h2x8Vendor AdvisoryPatch
FAQ
What is CVE-2025-69225?
CVE-2025-69225 is a vulnerability with a CVSS score of 5.3 (MEDIUM). AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the Range header. There ...
How severe is CVE-2025-69225?
CVE-2025-69225 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-69225?
Check the references section above for vendor advisories and patch information. Affected products include: Aiohttp Aiohttp.