CVE-2026-69243

Aliases:GHSA-mfx4-hv73-q22vPYSEC-2026-3546UBUNTU-CVE-2026-69243DEBIAN-CVE-2026-69243CGA-29fm-3gc2-wm9xCGA-43v4-c2mg-4mf6CGA-49qh-w2f8-9c6xCGA-9x96-qwx7-5523CGA-hj34-r7hq-jxq3CGA-j76c-6jgq-r993CGA-p4pq-cqph-frfmCGA-22wg-983w-r6fhCGA-2rw9-vpqv-x59rCGA-36x2-4g72-85x2CGA-3prx-27jf-g3rgCGA-3x8r-q3g7-f6rxCGA-5fm6-4vc4-mqjgCGA-5jfh-75q3-x7cvCGA-5mqq-mcr5-w7xjCGA-5vc6-457x-m6mhCGA-6wq8-27r8-p74qCGA-75g3-gw8f-8qxvCGA-8j8h-3xrq-qc5wCGA-8mrg-gc43-qrmjCGA-8xff-832p-vjcvCGA-9jj7-wxg6-93mpCGA-9mr7-xj6c-gp76CGA-c5wx-77rj-hr39CGA-f4q2-2rq2-j2xqCGA-hr26-jcr7-hqgjCGA-j4v7-3wvg-x47fCGA-m48w-6wxj-9xppCGA-mfxr-hx4m-6426CGA-mvpg-6wfj-8gmhCGA-pqmw-97hm-fx93CGA-qj5p-m7ph-cmjjCGA-qq8q-9m3r-7x8rCGA-r3c4-63vm-4jh3CGA-r6rr-wcxc-9mc6CGA-r9xv-hw8j-h26rCGA-rhxg-m658-gfh6CGA-rr77-8rp9-fvgrCGA-rvmc-r8pm-mp8hCGA-rwjr-2f24-jwqvCGA-v494-9r9w-9vhxCGA-w4fv-fjq2-82jqCGA-4wq8-6p95-mr9gCGA-g5w9-hgrm-mvvjCGA-q5gm-xprm-9jhhCGA-xwqq-wrvv-q56p
Awaiting Analysis
Published: 03 Aug 2026, 20:45
Last modified:05 Aug 2026, 14:54

Vulnerability Summary

Overall Risk (default)
medium
25/100
CVSS Score
6.3 MEDIUM
v4.0 (cve.org)
EPSS Score
0.43% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

03 Aug 2026, 20:45
Published
Vulnerability first disclosed
05 Aug 2026, 14:54
Last Modified
Vulnerability information updated

Description

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were vulnerable to a request smuggling attack relating to WebSocket upgrades. If using the server-side component, an attacker may be able to execute a request smuggling vulnerability using an edge case in the WebSocket upgrade procedure. A WebSocket upgrade request with a body could cause the parser to switch protocols before the complete request body was received, leaving trailing bytes to be handled as upgraded-protocol or pipelined data rather than normal HTTP body data. This issue is fixed in version 3.14.2.

CVSS Metrics

  • v4.0MEDIUMScore: 6.3CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
  • v4.0MEDIUMScore: 6.3CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS Trends

Current EPSS score: 0.43% Percentile: 37%

Techniques & Countermeasures

  • CWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

    The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

Affected Systems

  • aio-libsaiohttp

    < 3.14.2

  • chainguardairflow-2

    all

  • chainguardairflow-3

    < 3.3.1-r1 | < 3.3.0-r4

  • chainguardairflow-3-iamguarded-compat

    all

  • chainguardairflow-core-2

    < 2.11.2-r6

  • chainguardapache-beam-python-3.11-sdk

    < 2.75.0-r2

  • chainguardapache-beam-python-3.12-sdk

    < 2.75.0-r1

  • chainguardapache-beam-python-3.13-sdk

    < 2.75.0-r2

  • chainguardawx

    < 24.6.1-r49

  • chainguarddask-kubernetes

    < 2026.3.0-r11

  • chainguarddask-kubernetes-fips

    < 2026.3.0-r5 | < 2026.3.0-r6

  • chainguarddatahub-ingestion-fips

    < 1.6.0-r9

  • chainguardkserve

    < 0.20.0-r7

  • chainguardkserve-localmodel

    < 0.20.0-r7

  • chainguardkserve-models-web-app

    < 1.0.1-r2

  • chainguardkserve-storage-controller

    < 0.19.0-r5 | all | < 0.20.0-r7

  • chainguardlmcache-cuda-12.8

    < 0.5.3-r0

  • chainguardopen-webui

    < 0.11.0-r6

  • chainguardpuppygraph-python

    < 0.1.6-r2

  • chainguardpy3-cassandra-medusa

    < 0.29.1-r1

  • chainguardpy3.10-vllm-cuda-12.4

    < 0.18.1-r7

  • chainguardpy3.12-vllm-cuda-12.4

    < 0.18.1-r7

  • chainguardpy3.13-scanner-test-libraries-aiohttp

    < 0.0.1-r4

  • chainguardtext-generation-inference

    < 3.3.7-r23

  • chainguardtritonserver-backend-vllm-cuda-13.0

    < 25.11-r11

  • wolfiairflow-3

    < 3.3.1-r1 | < 3.3.0-r4

  • wolfiairflow-3-iamguarded-compat

    all

  • wolfidask-kubernetes

    < 2026.3.0-r11

  • wolfikserve

    < 0.20.0-r7

  • wolfikserve-localmodel

    < 0.20.0-r7

  • wolfikserve-storage-controller

    < 0.19.0-r5 | all | < 0.20.0-r7

  • wolfiopen-webui

    < 0.11.0-r6

  • wolfipy3-cassandra-medusa

    < 0.29.1-r1

  • debianpython-aiohttp

    all | all | all | all

  • ubuntupython-aiohttp

    all

  • PyPIaiohttp

    < 3.14.2

References (12)