CVE-2026-69244

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response. An attacker controlled server, or possibly an accidental response, could trigger a DoS in the client. The vulnerable path was error message construction in aiohttp/_http_parser.pyx, where an llhttp error-position pointer was used to build a snippet for malformed chunked responses and malformed request or response bytes at the buffer end. This issue is fixed in version 3.14.3.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-03 21:16

Updated : 2026-09-10 20:36


NVD link : CVE-2026-69244

Mitre link : CVE-2026-69244

CVE.ORG link : CVE-2026-69244


JSON object : View

Products Affected

No product.

CWE
CWE-125

Out-of-bounds Read

CWE-400

Uncontrolled Resource Consumption

CWE-416

Use After Free