CVE-2026-69244 with a CVSS score of 7.1 is a vulnerability affecting aiohttp versions <= 3.14.2 in aiohttp that allows an out-of-bounds heap read in the C HTTP response parser error path, which could occur when building an error message for a malformed chunked response. This flaw type can be exploited via the environment template management API by an attacker-controlled server or possibly an accidental response, triggering a DoS in the client. The business impact of this vulnerability is significant, as it can lead to a denial-of-service condition in the client application. The affected versions are prior to 3.14.3, and the impacted component is the rating block's custom icon rendering component.
We recommend you to update aiohttp to version 3.14.3.[/subscribe_to_unlock_form]
CVE-2026-69244 with a CVSS score of 7.1 is a vulnerability affecting aiohttp versions <= 3.14.2 in aiohttp that allows an out-of-bounds heap read in the C HTTP response parser error path, which could occur when building an error message for a malformed chunked response. This flaw type can be exploited via the environment template management API by an attacker-controlled server or possibly an accidental response, triggering a DoS in the client. The business impact of this vulnerability is significant, as it can lead to a denial-of-service condition in the client application. The affected versions are prior to 3.14.3, and the impacted component is the rating block's custom icon rendering component.
We recommend you to update aiohttp to version 3.14.3.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]