Threat Advisory

AIOHTTP Flaw Triggers Out-of-Bounds Heap Read and Possible Client DoS

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-69244 with a CVSS score of 7.1 is a vulnerability affecting aiohttp versions <= 3.14.2 in aiohttp that allows an out-of-bounds heap read in the C HTTP response parser error path, which could occur when building an error message for a malformed chunked response. This flaw type can be exploited via the environment template management API by an attacker-controlled server or possibly an accidental response, triggering a DoS in the client. The business impact of this vulnerability is significant, as it can lead to a denial-of-service condition in the client application. The affected versions are prior to 3.14.3, and the impacted component is the rating block's custom icon rendering component.

RECOMMENDATION:

We recommend you to update aiohttp to version 3.14.3.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-69244 with a CVSS score of 7.1 is a vulnerability affecting aiohttp versions <= 3.14.2 in aiohttp that allows an out-of-bounds heap read in the C HTTP response parser error path, which could occur when building an error message for a malformed chunked response. This flaw type can be exploited via the environment template management API by an attacker-controlled server or possibly an accidental response, triggering a DoS in the client. The business impact of this vulnerability is significant, as it can lead to a denial-of-service condition in the client application. The affected versions are prior to 3.14.3, and the impacted component is the rating block's custom icon rendering component.

RECOMMENDATION:

We recommend you to update aiohttp to version 3.14.3.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu