CVE-2025-69223

Red Hat Security Advisory: RHOAI 3.3.5 - Red Hat OpenShift AI

Description

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust the host's memory. This issue is fixed in version 3.13.3.

Metrics

Severity
high
no public PoC known
7.5
Source: nvd-v3
45.3 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
0.6 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-09 11:57 UTC
CWE-409, CWE-770

Weakness classes (CWE)

  • CWE-409Base

    Improper Handling of Highly Compressed Data (Data Amplification)

    The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

    cwe.mitre.org →
  • CWE-770Base

    Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-09-09 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2025/69xxx/CVE-2025-69223.json">CVE-2025-69223</a>
  2. CVE Modified2026-09-01 13:18 UTC· security-advisories@github.com
    • Reference: https://github.com/aio-libs/aiohttp/commit/2b920c39002cee0ec5b402581779bbaaf7c9138a
    • Reference: https://github.com/aio-libs/aiohttp/security/advisories/GHSA-6mq8-rvhq-8wgg
    • Reference: https://github.com/aio-libs/aiohttp/commit/2b920c39002cee0ec5b402581779bbaaf7c9138a
    • Reference: https://github.com/aio-libs/aiohttp/security/advisories/GHSA-6mq8-rvhq-8wgg
  3. CVE Modified2026-09-01 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:10184
    • Reference: https://access.redhat.com/errata/RHSA-2026:1249
    • Reference: https://access.redhat.com/errata/RHSA-2026:1497
    • Reference: https://access.redhat.com/errata/RHSA-2026:1506
  4. CVE Modified2026-08-25 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:59155
    • Reference: https://access.redhat.com/errata/RHSA-2026:59159
    • Affected: Red Hat Ansible Automation Platform 2.4 for RHEL 8, Red Hat Ansible Automation Platform 2.4 for RHEL 9, Red Hat Ansible Automation Platform 2.5 for RHEL 8 (+129)Red Hat Ansible Automation Platform 2.4 for RHEL 8, Red Hat Ansible Automation Platform 2.4 for RHEL 9, Red Hat Ansible Automation Platform 2.5 for RHEL 8 (+129)
  5. CVE Modified2026-08-24 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Red Hat Ansible Automation Platform 2.4 for RHEL 8, Red Hat Ansible Automation Platform 2.4 for RHEL 9, Red Hat Ansible Automation Platform 2.5 for RHEL 8 (+129)Red Hat Ansible Automation Platform 2.4 for RHEL 8, Red Hat Ansible Automation Platform 2.4 for RHEL 9, Red Hat Ansible Automation Platform 2.5 for RHEL 8 (+129)

Affected operating systems

  • linux

    debian / debian_linux11.0

  • linux

    redhat / enterprise_linux_ai3.0

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • aiohttp

    aiohttp3.13.3

  • aiohttp

    aiohttp3.14.0

  • bitnami

    mlflow

  • cryptography.io

    cryptography45.0.0 – 46.0.7

  • danthedeckie

    simpleeval1.0.5

  • encode

    starlette0.8.3 – 1.0.1

  • golang

    crypto0.52.0

  • golang

    go1.25.0 – 1.25.6

  • golang

    go1.24.12

  • grpc

    grpc1.79.3

  • huggingface

    transformers

  • IBM

    Concert< 3.0.0

    fixed in 3.0.0

  • IBM

    QRadar SIEM<7.5.0 UP15 IF06

  • keras

    keras

  • langchain

    langchain_core1.2.22

  • nltk

    nltk3.9.3

  • protobufjs_project

    protobufjs7.5.5

  • protobufjs_project

    protobufjs

  • pyasn1

    pyasn10.6.2

  • pyasn1

    pyasn10.6.3

  • pyjwt_project

    pyjwt2.12.0

  • pyjwt_project

    pyjwt2.13.0

  • pypa

    pip26.1.2

  • pypi

    multipart0.1

References & sources

Linked CVEs

Show 7 more CVEs
IDCVE-2025-69223