CVE-2025-69229: AIOHTTP vulnerable to DoS through chunked messages
Summary
Handling of chunked messages can result in excessive blocking CPU usage when receiving a large number of chunks.
Impact
If an application makes use of the request.read() method in an endpoint, it may be possible for an attacker to cause the server to spend a moderate amount of blocking CPU time (e.g. 1 second) while processing the request. This could potentially lead to DoS as the server would be unable to handle other requests during that time.
-----
Patch: https://github.com/aio-libs/aiohttp/commit/dc3170b56904bdf814228fae70a5501a42a6c712 Patch: https://github.com/aio-libs/aiohttp/commit/4ed97a4e46eaf61bd0f05063245f613469700229
Other sources
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling of chunked messages can result in excessive blocking CPU usage when receiving a large number of chunks. If an application makes use of the request.read() method in an endpoint, it may be possible for an attacker to cause the server to spend a moderate amount of blocking CPU time (e.g. 1 second) while processing the request. This could potentially lead to DoS as the server would be unable to handle other requests during that time. This issue is fixed in version 3.13.3.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-69229?
CVE-2025-69229 is considered a moderate severity vulnerability due to its potential to cause excessive CPU usage.
How do I fix CVE-2025-69229?
To fix CVE-2025-69229, upgrade the aiohttp package to version 3.13.3 or above.
What causes the issue in CVE-2025-69229?
CVE-2025-69229 arises from improper handling of chunked messages, leading to blocking CPU usage in affected applications.
Who is affected by CVE-2025-69229?
CVE-2025-69229 affects applications that utilize the request.read() method in conjunction with aiohttp versions prior to 3.13.3.
What symptoms indicate an exploitation of CVE-2025-69229?
Indicators of exploitation for CVE-2025-69229 may include unusually high CPU usage on the server when handling chunked requests.