Async http client/server framework (asyncio).
Security Fix(es):
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the Range header. There is no known impact, but there is the possibility that there's a method to exploit a request smuggling vulnerability. This issue is fixed in version 3.13.3.(CVE-2025-69225)
aiohttp contains a denial-of-service vulnerability when bypassing asserts, allowing attackers to bypass assertion checks through specific methods leading to service unavailability.(CVE-2025-69227)
aiohttp contains a vulnerability when processing large payloads. An attacker can craft large requests to exhaust server resources, leading to denial of service.(CVE-2025-69228)
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling of chunked messages can result in excessive blocking CPU usage when receiving a large number of small chunks. If an application makes use of the request.read() method in an endpoint, it may be possible for an attacker to cause the server to spend a moderate amount of blocking CPU time (e.g., 1 second) while processing the request. This could potentially lead to a Denial of Service (DoS) as the server would be unable to handle other requests during that time.(CVE-2025-69229)
{
"severity": "Medium"
}{
"src": [
"python-aiohttp-3.7.4-6.oe2003sp4.src.rpm"
],
"x86_64": [
"python-aiohttp-debuginfo-3.7.4-6.oe2003sp4.x86_64.rpm",
"python-aiohttp-debugsource-3.7.4-6.oe2003sp4.x86_64.rpm",
"python-aiohttp-help-3.7.4-6.oe2003sp4.x86_64.rpm",
"python3-aiohttp-3.7.4-6.oe2003sp4.x86_64.rpm"
],
"aarch64": [
"python-aiohttp-debuginfo-3.7.4-6.oe2003sp4.aarch64.rpm",
"python-aiohttp-debugsource-3.7.4-6.oe2003sp4.aarch64.rpm",
"python-aiohttp-help-3.7.4-6.oe2003sp4.aarch64.rpm",
"python3-aiohttp-3.7.4-6.oe2003sp4.aarch64.rpm"
]
}{
"src": [
"python-aiohttp-3.7.4-7.oe2203sp4.src.rpm"
],
"x86_64": [
"python-aiohttp-debuginfo-3.7.4-7.oe2203sp4.x86_64.rpm",
"python-aiohttp-debugsource-3.7.4-7.oe2203sp4.x86_64.rpm",
"python-aiohttp-help-3.7.4-7.oe2203sp4.x86_64.rpm",
"python3-aiohttp-3.7.4-7.oe2203sp4.x86_64.rpm"
],
"aarch64": [
"python-aiohttp-debuginfo-3.7.4-7.oe2203sp4.aarch64.rpm",
"python-aiohttp-debugsource-3.7.4-7.oe2203sp4.aarch64.rpm",
"python-aiohttp-help-3.7.4-7.oe2203sp4.aarch64.rpm",
"python3-aiohttp-3.7.4-7.oe2203sp4.aarch64.rpm"
]
}{
"src": [
"python-aiohttp-3.9.3-9.oe2403sp1.src.rpm",
"python-aiohttp-3.9.3-9.oe2403sp2.src.rpm",
"python-aiohttp-3.9.3-9.oe2403sp3.src.rpm",
"python-aiohttp-3.9.3-9.oe2403.src.rpm"
],
"x86_64": [
"python-aiohttp-debuginfo-3.9.3-9.oe2403sp1.x86_64.rpm",
"python-aiohttp-debugsource-3.9.3-9.oe2403sp1.x86_64.rpm",
"python-aiohttp-help-3.9.3-9.oe2403sp1.x86_64.rpm",
"python3-aiohttp-3.9.3-9.oe2403sp1.x86_64.rpm",
"python-aiohttp-debuginfo-3.9.3-9.oe2403sp2.x86_64.rpm",
"python-aiohttp-debugsource-3.9.3-9.oe2403sp2.x86_64.rpm",
"python-aiohttp-help-3.9.3-9.oe2403sp2.x86_64.rpm",
"python3-aiohttp-3.9.3-9.oe2403sp2.x86_64.rpm",
"python-aiohttp-debuginfo-3.9.3-9.oe2403sp3.x86_64.rpm",
"python-aiohttp-debugsource-3.9.3-9.oe2403sp3.x86_64.rpm",
"python-aiohttp-help-3.9.3-9.oe2403sp3.x86_64.rpm",
"python3-aiohttp-3.9.3-9.oe2403sp3.x86_64.rpm",
"python-aiohttp-debuginfo-3.9.3-9.oe2403.x86_64.rpm",
"python-aiohttp-debugsource-3.9.3-9.oe2403.x86_64.rpm",
"python-aiohttp-help-3.9.3-9.oe2403.x86_64.rpm",
"python3-aiohttp-3.9.3-9.oe2403.x86_64.rpm"
],
"aarch64": [
"python-aiohttp-debuginfo-3.9.3-9.oe2403sp1.aarch64.rpm",
"python-aiohttp-debugsource-3.9.3-9.oe2403sp1.aarch64.rpm",
"python-aiohttp-help-3.9.3-9.oe2403sp1.aarch64.rpm",
"python3-aiohttp-3.9.3-9.oe2403sp1.aarch64.rpm",
"python-aiohttp-debuginfo-3.9.3-9.oe2403sp2.aarch64.rpm",
"python-aiohttp-debugsource-3.9.3-9.oe2403sp2.aarch64.rpm",
"python-aiohttp-help-3.9.3-9.oe2403sp2.aarch64.rpm",
"python3-aiohttp-3.9.3-9.oe2403sp2.aarch64.rpm",
"python-aiohttp-debuginfo-3.9.3-9.oe2403sp3.aarch64.rpm",
"python-aiohttp-debugsource-3.9.3-9.oe2403sp3.aarch64.rpm",
"python-aiohttp-help-3.9.3-9.oe2403sp3.aarch64.rpm",
"python3-aiohttp-3.9.3-9.oe2403sp3.aarch64.rpm",
"python-aiohttp-debuginfo-3.9.3-9.oe2403.aarch64.rpm",
"python-aiohttp-debugsource-3.9.3-9.oe2403.aarch64.rpm",
"python-aiohttp-help-3.9.3-9.oe2403.aarch64.rpm",
"python3-aiohttp-3.9.3-9.oe2403.aarch64.rpm"
]
}{
"src": [
"python-aiohttp-3.9.3-9.oe2403sp1.src.rpm"
],
"x86_64": [
"python-aiohttp-debuginfo-3.9.3-9.oe2403sp1.x86_64.rpm",
"python-aiohttp-debugsource-3.9.3-9.oe2403sp1.x86_64.rpm",
"python-aiohttp-help-3.9.3-9.oe2403sp1.x86_64.rpm",
"python3-aiohttp-3.9.3-9.oe2403sp1.x86_64.rpm"
],
"aarch64": [
"python-aiohttp-debuginfo-3.9.3-9.oe2403sp1.aarch64.rpm",
"python-aiohttp-debugsource-3.9.3-9.oe2403sp1.aarch64.rpm",
"python-aiohttp-help-3.9.3-9.oe2403sp1.aarch64.rpm",
"python3-aiohttp-3.9.3-9.oe2403sp1.aarch64.rpm"
]
}{
"src": [
"python-aiohttp-3.9.3-9.oe2403sp2.src.rpm"
],
"x86_64": [
"python-aiohttp-debuginfo-3.9.3-9.oe2403sp2.x86_64.rpm",
"python-aiohttp-debugsource-3.9.3-9.oe2403sp2.x86_64.rpm",
"python-aiohttp-help-3.9.3-9.oe2403sp2.x86_64.rpm",
"python3-aiohttp-3.9.3-9.oe2403sp2.x86_64.rpm"
],
"aarch64": [
"python-aiohttp-debuginfo-3.9.3-9.oe2403sp2.aarch64.rpm",
"python-aiohttp-debugsource-3.9.3-9.oe2403sp2.aarch64.rpm",
"python-aiohttp-help-3.9.3-9.oe2403sp2.aarch64.rpm",
"python3-aiohttp-3.9.3-9.oe2403sp2.aarch64.rpm"
]
}{
"src": [
"python-aiohttp-3.9.3-9.oe2403sp3.src.rpm"
],
"x86_64": [
"python-aiohttp-debuginfo-3.9.3-9.oe2403sp3.x86_64.rpm",
"python-aiohttp-debugsource-3.9.3-9.oe2403sp3.x86_64.rpm",
"python-aiohttp-help-3.9.3-9.oe2403sp3.x86_64.rpm",
"python3-aiohttp-3.9.3-9.oe2403sp3.x86_64.rpm"
],
"aarch64": [
"python-aiohttp-debuginfo-3.9.3-9.oe2403sp3.aarch64.rpm",
"python-aiohttp-debugsource-3.9.3-9.oe2403sp3.aarch64.rpm",
"python-aiohttp-help-3.9.3-9.oe2403sp3.aarch64.rpm",
"python3-aiohttp-3.9.3-9.oe2403sp3.aarch64.rpm"
]
}