Request Smuggling Vulnerability in AIOHTTP Framework by aio-libs
CVE-2025-53643

1.7LOW

Key Information:

Vendor

Aio-libs

Status
Vendor
CVE Published:
14 July 2025

What is CVE-2025-53643?

The AIOHTTP framework, an asynchronous HTTP client/server for Python, contains a vulnerability prior to version 3.12.14 that allows for request smuggling attacks. This flaw arises from improper parsing of trailer sections in HTTP requests, particularly when the pure Python version is used without the accompanying C extensions or if AIOHTTP_NO_EXTENSIONS is enabled. Attackers may exploit this vulnerability to bypass certain firewall and proxy protections, emphasizing the importance of upgrading to version 3.12.14 or later.

Affected Version(s)

aiohttp < 3.12.14

References

CVSS V4

Score:
1.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53643 : Request Smuggling Vulnerability in AIOHTTP Framework by aio-libs