CVE Vulnerabilities

CVE-2025-69223

Improper Handling of Highly Compressed Data (Data Amplification)

Published: Jan 05, 2026 | Modified: Jan 14, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust the hosts memory. This issue is fixed in version 3.13.3.

Weakness

The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

Affected Software

NameVendorStart VersionEnd Version
AiohttpAiohttp*3.13.3 (excluding)
Red Hat Ansible Automation Platform 2.4 for RHEL 8RedHatautomation-controller-0:4.5.30-1.el8ap*
Red Hat Ansible Automation Platform 2.4 for RHEL 9RedHatautomation-controller-0:4.5.30-1.el9ap*
Red Hat Ansible Automation Platform 2.5 for RHEL 8RedHatautomation-controller-0:4.6.25-1.el8ap*
Red Hat Ansible Automation Platform 2.5 for RHEL 9RedHatautomation-controller-0:4.6.25-1.el9ap*
Red Hat Ansible Automation Platform 2.6 for RHEL 9RedHatautomation-controller-0:4.7.8-1.el9ap*
Red Hat Ansible Automation Platform 2.4RedHatansible-automation-platform-24/controller-rhel8:sha256:6407934968d4a6b83164a2d11870e46ab781c14445ab809b55acb9ce32b3a450*
Red Hat Ansible Automation Platform 2.6RedHatansible-automation-platform-26/controller-rhel9:sha256:bb334abcc74bbebff0442393d370d7a4990097b275cf46761933a7fd61d94c87*
Red Hat Ansible Automation Platform 2.6RedHatansible-automation-platform-26/de-minimal-rhel9:sha256:7f64dd39779023cd008c3237b60b419821985d658d24429b92070db9224b2629*
Red Hat Ansible Automation Platform 2.6RedHatansible-automation-platform-26/de-supported-rhel9:sha256:1dd6b6b9d9426175830de6066033115287ec259d118d5214582730209f3b3e63*
Python-aiohttpUbuntuplucky*

References