CVE-2025-69230

Publication date 6 January 2026

Last updated 5 February 2026


Ubuntu priority

Description

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can lead to a logging storm. If the cookies attribute is accessed in an application, then an attacker may be able to trigger a storm of warning-level logs using a specially crafted Cookie header. This issue is fixed in 3.13.3.

Status

Package Ubuntu Release Status
python-aiohttp 25.10 questing Ignored code not present
25.04 plucky Ignored end of life, was needs-triage
24.04 LTS noble Ignored code not present
22.04 LTS jammy Ignored code not present
20.04 LTS focal Ignored code not present
18.04 LTS bionic Ignored code not present
16.04 LTS xenial Ignored code not present

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
python-aiohttp