Request Smuggling Vulnerability in AIOHTTP Framework by aio-libs
CVE-2025-69225
What is CVE-2025-69225?
The AIOHTTP framework, utilized for building asynchronous HTTP clients and servers in Python, contains a vulnerability in versions 3.13.2 and earlier. This flaw permits the inclusion of non-ASCII decimals in the Range header, potentially paving the way for a request smuggling attack. Although no direct impacts have been reported, this issue highlights the importance of keeping dependencies updated. The vulnerability has been addressed in version 3.13.3, providing users with a crucial upgrade path to enhance security. For additional information on this vulnerability, refer to the official advisory and commit notes.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
aiohttp < 3.13.3
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
