From =?UTF-8?Q?Moritz_M=C3=BChlenhoff?=@21:1/5 to All on Tue Jul 15 14:40:01 2025
Package: python-aiohttp
X-Debbugs-CC: [email protected]
Severity: important
Tags: security
Hi,
The following vulnerability was published for python-aiohttp.
CVE-2025-53643[0]:
| AIOHTTP is an asynchronous HTTP client/server framework for asyncio
| and Python. Prior to version 3.12.14, the Python parser is
| vulnerable to a request smuggling vulnerability due to not parsing
| trailer sections of an HTTP request. If a pure Python version of
| aiohttp is installed (i.e. without the usual C extensions) or
| AIOHTTP_NO_EXTENSIONS is enabled, then an attacker may be able to
| execute a request smuggling attack to bypass certain firewalls or
| proxy protections. Version 3.12.14 contains a patch for this issue.