Vulnerability Description
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can lead to a logging storm. If the cookies attribute is accessed in an application, then an attacker may be able to trigger a storm of warning-level logs using a specially crafted Cookie header. This issue is fixed in 3.13.3.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aiohttp | Aiohttp | < 3.13.3 |
Related Weaknesses (CWE)
References
- https://github.com/aio-libs/aiohttp/commit/64629a0834f94e46d9881f4e99c41a137e1f3Patch
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-fh55-r93g-j68gVendor AdvisoryPatch
FAQ
What is CVE-2025-69230?
CVE-2025-69230 is a vulnerability with a CVSS score of 5.3 (MEDIUM). AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can lead to a logging storm. If the cookies attribute is ...
How severe is CVE-2025-69230?
CVE-2025-69230 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-69230?
Check the references section above for vendor advisories and patch information. Affected products include: Aiohttp Aiohttp.