CVE-2025-69223
Red Hat Security Advisory: RHOAI 3.3.5 - Red Hat OpenShift AI
Description
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust the host's memory. This issue is fixed in version 3.13.3.
Metrics
Weakness classes (CWE)
CWE-409Base
Improper Handling of Highly Compressed Data (Data Amplification)
The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.
cwe.mitre.org →CWE-770Base
Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
cwe.mitre.org →
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-09-09 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2025/69xxx/CVE-2025-69223.json">CVE-2025-69223</a>
- CVE Modified2026-09-01 13:18 UTC· security-advisories@github.com
- Reference: https://github.com/aio-libs/aiohttp/commit/2b920c39002cee0ec5b402581779bbaaf7c9138a
- Reference: https://github.com/aio-libs/aiohttp/security/advisories/GHSA-6mq8-rvhq-8wgg
- Reference: https://github.com/aio-libs/aiohttp/commit/2b920c39002cee0ec5b402581779bbaaf7c9138a
- Reference: https://github.com/aio-libs/aiohttp/security/advisories/GHSA-6mq8-rvhq-8wgg
- CVE Modified2026-09-01 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Reference: https://access.redhat.com/errata/RHSA-2026:10184
- Reference: https://access.redhat.com/errata/RHSA-2026:1249
- Reference: https://access.redhat.com/errata/RHSA-2026:1497
- Reference: https://access.redhat.com/errata/RHSA-2026:1506
- CVE Modified2026-08-25 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Reference: https://access.redhat.com/errata/RHSA-2026:59155
- Reference: https://access.redhat.com/errata/RHSA-2026:59159
- Affected: Red Hat Ansible Automation Platform 2.4 for RHEL 8, Red Hat Ansible Automation Platform 2.4 for RHEL 9, Red Hat Ansible Automation Platform 2.5 for RHEL 8 (+129) → Red Hat Ansible Automation Platform 2.4 for RHEL 8, Red Hat Ansible Automation Platform 2.4 for RHEL 9, Red Hat Ansible Automation Platform 2.5 for RHEL 8 (+129)
- CVE Modified2026-08-24 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Red Hat Ansible Automation Platform 2.4 for RHEL 8, Red Hat Ansible Automation Platform 2.4 for RHEL 9, Red Hat Ansible Automation Platform 2.5 for RHEL 8 (+129) → Red Hat Ansible Automation Platform 2.4 for RHEL 8, Red Hat Ansible Automation Platform 2.4 for RHEL 9, Red Hat Ansible Automation Platform 2.5 for RHEL 8 (+129)
Affected operating systems
linux
debian / debian_linux11.0
linux
redhat / enterprise_linux_ai3.0
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
aiohttp
aiohttp3.13.3
aiohttp
aiohttp3.14.0
bitnami
mlflow
cryptography.io
cryptography45.0.0 – 46.0.7
danthedeckie
simpleeval1.0.5
encode
starlette0.8.3 – 1.0.1
golang
crypto0.52.0
golang
go1.25.0 – 1.25.6
golang
go1.24.12
grpc
grpc1.79.3
huggingface
transformers
IBM
Concert< 3.0.0
fixed in 3.0.0
IBM
QRadar SIEM<7.5.0 UP15 IF06
keras
keras
langchain
langchain_core1.2.22
nltk
nltk3.9.3
protobufjs_project
protobufjs7.5.5
protobufjs_project
protobufjs
pyasn1
pyasn10.6.2
pyasn1
pyasn10.6.3
pyjwt_project
pyjwt2.12.0
pyjwt_project
pyjwt2.13.0
pypa
pip26.1.2
pypi
multipart0.1
References & sources
- https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-xq3m-2v4x-88ggweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-41242advisory
- https://github.com/protobufjs/protobuf.js/commit/535df444ac060243722ac5d672db205e5c531d75web
- https://github.com/protobufjs/protobuf.js/commit/ff7b2afef8754837cc6dc64c864cd111ab477956web
- https://github.com/protobufjs/protobuf.jspackage
- https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.5.5web
- https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v8.0.1web
- https://access.redhat.com/security/cve/CVE-2026-41242vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2459442issue-trackingx_refsource_REDHAT
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41242.jsonx_sadp-csaf-vex
- https://access.redhat.com/errata/RHSA-2026:21338vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:26234vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:24977vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:37275vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:62260vendor-advisoryx_refsource_REDHAT
- https://github.com/remix-run/react-router/security/advisories/GHSA-8646-j5j9-6r62web
- https://nvd.nist.gov/vuln/detail/CVE-2026-33245advisory
- https://github.com/remix-run/react-routerpackage
- https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wxevidence
- https://access.redhat.com/security/cve/CVE-2026-48526vdb-entryx_refsource_REDHAT
Linked CVEs
- CVE-2026-8643
A flaw was found in pip, the package installer for Python.
highCVSSv3 8.0 - CVE-2026-5241
A flaw was found in python-transformers.
criticalCVSSv3 9.6 - CVE-2026-48710Actively exploited
A flaw was found in Starlette, a lightweight ASGI (Asynchronous Server Gateway Interface) framework.
criticalCVSSv3 6.5 - CVE-2026-48526
A flaw was found in PyJWT, a Python library for JSON Web Token (JWT) implementation.
highCVSSv3 7.4 - CVE-2026-46595
A flaw was found in golang.org/x/crypto/ssh.
criticalCVSSv3 10.0 - CVE-2026-44432
urllib3 is an HTTP client library for Python.
highCVSSv3 7.5 - CVE-2026-44431
A flaw was found in urllib3, an HTTP client library for Python.
high - CVE-2026-42561
A flaw was found in python-multipart.
highCVSSv3 7.5 - CVE-2026-41242
A flaw was found in protobufjs, a JavaScript (JS) library used for compiling protobuf definitions.
criticalCVSSv3 9.8 - CVE-2026-40192
A flaw was found in Pillow, a Python imaging library.
highCVSSv3 7.5 - CVE-2026-39892
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers.
criticalCVSSv3 9.8 - CVE-2026-39830
A flaw was found in golang.org/x/crypto/ssh.
criticalCVSSv3 9.1 - CVE-2026-35536
A flaw was found in Tornado.
highCVSSv3 7.2 - CVE-2026-34993
A flaw was found in AIOHTTP, an asynchronous HTTP client/server framework for asyncio and Python.
highCVSSv3 7.3 - CVE-2026-34070
A flaw was found in LangChain.
highCVSSv3 7.5 - CVE-2026-33699
A flaw was found in pypdf.
medium - CVE-2026-33245
A flaw was found in React Router.
highCVSSv3 8.0 - CVE-2026-33236
A flaw was found in NLTK (Natural Language Toolkit), a suite of open-source Python modules for Natural Language Processing.
highCVSSv3 8.1 - CVE-2026-33231
A flaw was found in NLTK (Natural Language Toolkit), specifically in the `nltk.app.wordnet_app` component.
highCVSSv3 7.5 - CVE-2026-33186
A flaw was found in gRPC-Go, the Go language implementation of gRPC.
criticalCVSSv3 9.1 - CVE-2026-32640
A flaw was found in the Python library, SimpleEval.
criticalCVSSv3 9.8 - CVE-2026-32597
PyJWT is a JSON Web Token implementation in Python.
highCVSSv3 7.5 - CVE-2026-31958
A flaw was found in tornado-python.
high - CVE-2026-30922
An unbounded recursion flaw has been discovered in the pypi pyasn1 library.
highCVSSv3 7.5
Show 7 more CVEs
- CVE-2026-28684
A flaw was found in python-dotenv.
mediumCVSSv3 6.6 - CVE-2026-28356
A flaw was found in multipart.
highCVSSv3 7.5 - CVE-2026-27893
A flaw was found in vLLM, an inference and serving engine for large language models (LLMs).
highCVSSv3 8.8 - CVE-2026-2614
A flaw was found in mlflow.
highCVSSv3 7.5 - CVE-2026-23490
A flaw was found in pyasn1, a generic ASN.1 library for Python.
highCVSSv3 7.5 - CVE-2026-1462
A flaw was found in the `keras` package.
highCVSSv3 8.8 - CVE-2025-61726
The net/url package does not set a limit on the number of query parameters in a query.
highCVSSv3 7.5