CVE-2025-53643
published 2025-07-14CVE-2025-53643: AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.30%
21.6th percentile
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability due to not parsing trailer sections of an HTTP request. If a pure Python version of aiohttp is installed (i.e. without the usual C extensions) or AIOHTTP_NO_EXTENSIONS is enabled, then an attacker may be able to execute a request smuggling attack to bypass certain firewalls or proxy protections. Version 3.12.14 contains a patch for this issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| aio-libs | aiohttp | < 3.12.14 | 3.12.14 |
| aiohttp | aiohttp | < 3.12.14 | 3.12.14 |
| aiohttp | aiohttp | >= 0 < 3.12.14 | 3.12.14 |
| debian | python-aiohttp | < python-aiohttp 3.12.15-1 (forky) | python-aiohttp 3.12.15-1 (forky) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv4.01.7LOWCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv1.7LOW
vendor_oracle7.5LOW
vendor_debian1.7LOW
vendor_redhat1.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Siebel CRM Risk Matrix: Siebel Cloud Manager (AIOHTTP) — CVE-2025-53643
vendor_oracle·2026-01-15·CVSS 7.5
CVE-2025-53643 [LOW] Oracle Oracle Siebel CRM Risk Matrix: Siebel Cloud Manager (AIOHTTP) — CVE-2025-53643
Oracle Oracle Siebel CRM Risk Matrix: Siebel Cloud Manager (AIOHTTP) vulnerability
CVE: CVE-2025-53643
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Oracle
Oracle Oracle Communications Risk Matrix: Developer Infrastructure (AIOHTTP) — CVE-2025-53643
vendor_oracle·2025-10-15·CVSS 7.5
CVE-2025-53643 [LOW] Oracle Oracle Communications Risk Matrix: Developer Infrastructure (AIOHTTP) — CVE-2025-53643
Oracle Oracle Communications Risk Matrix: Developer Infrastructure (AIOHTTP) vulnerability
CVE: CVE-2025-53643
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
Red Hat
aiohttp: AIOHTTP HTTP Request/Response Smuggling
vendor_redhat·2025-07-14·CVSS 1.7
CVE-2025-53643 [LOW] CWE-444 aiohttp: AIOHTTP HTTP Request/Response Smuggling
aiohttp: AIOHTTP HTTP Request/Response Smuggling
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability due to not parsing trailer sections of an HTTP request. If a pure Python version of aiohttp is installed (i.e. without the usual C extensions) or AIOHTTP_NO_EXTENSIONS is enabled, then an attacker may be able to execute a request smuggling attack to bypass certain firewalls or proxy protections. Version 3.12.14 contains a patch for this issue.
A request smuggling flaw was found in the aiohttp python library. If a pure Python version of aiohttp is installed, without the usual C extensions, for example, or if AIOHTTP_NO_EXTENSIONS is enabled, an attacker can execute a r
Debian
CVE-2025-53643: python-aiohttp - AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. ...
vendor_debian·2025·CVSS 1.7
CVE-2025-53643 [LOW] CVE-2025-53643: python-aiohttp - AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. ...
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability due to not parsing trailer sections of an HTTP request. If a pure Python version of aiohttp is installed (i.e. without the usual C extensions) or AIOHTTP_NO_EXTENSIONS is enabled, then an attacker may be able to execute a request smuggling attack to bypass certain firewalls or proxy protections. Version 3.12.14 contains a patch for this issue.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 3.12.15-1)
sid: resolved (fixed in 3.12.15-1)
trixie: open
GHSA
AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
ghsa·2025-07-14
CVE-2025-53643 [LOW] CWE-444 AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
### Summary
The Python parser is vulnerable to a request smuggling vulnerability due to not parsing trailer sections of an HTTP request.
### Impact
If a pure Python version of aiohttp is installed (i.e. without the usual C extensions) or AIOHTTP_NO_EXTENSIONS is enabled, then an attacker may be able to execute a request smuggling attack to bypass certain firewalls or proxy protections.
----
Patch: https://github.com/aio-libs/aiohttp/commit/e8d774f635dc6d1cd3174d0e38891da5de0e2b6a
OSV
CVE-2025-53643: AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python
osv·2025-07-14·CVSS 1.7
CVE-2025-53643 [LOW] CVE-2025-53643: AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability due to not parsing trailer sections of an HTTP request. If a pure Python version of aiohttp is installed (i.e. without the usual C extensions) or AIOHTTP_NO_EXTENSIONS is enabled, then an attacker may be able to execute a request smuggling attack to bypass certain firewalls or proxy protections. Version 3.12.14 contains a patch for this issue.
OSV
AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
osv·2025-07-14
CVE-2025-53643 [LOW] AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
### Summary
The Python parser is vulnerable to a request smuggling vulnerability due to not parsing trailer sections of an HTTP request.
### Impact
If a pure Python version of aiohttp is installed (i.e. without the usual C extensions) or AIOHTTP_NO_EXTENSIONS is enabled, then an attacker may be able to execute a request smuggling attack to bypass certain firewalls or proxy protections.
----
Patch: https://github.com/aio-libs/aiohttp/commit/e8d774f635dc6d1cd3174d0e38891da5de0e2b6a
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-53643 python-aiohttp-socks: AIOHTTP HTTP Request/Response Smuggling [fedora-42]
bugzilla·2025-07-14·CVSS 1.7
CVE-2025-53643 [LOW] CVE-2025-53643 python-aiohttp-socks: AIOHTTP HTTP Request/Response Smuggling [fedora-42]
CVE-2025-53643 python-aiohttp-socks: AIOHTTP HTTP Request/Response Smuggling [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug
Bugzilla
CVE-2025-53643 python-aiohttp-retry: AIOHTTP HTTP Request/Response Smuggling [fedora-42]
bugzilla·2025-07-14·CVSS 1.7
CVE-2025-53643 [LOW] CVE-2025-53643 python-aiohttp-retry: AIOHTTP HTTP Request/Response Smuggling [fedora-42]
CVE-2025-53643 python-aiohttp-retry: AIOHTTP HTTP Request/Response Smuggling [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug
Bugzilla
CVE-2025-53643 python-aiohttp-oauthlib: AIOHTTP HTTP Request/Response Smuggling [fedora-41]
bugzilla·2025-07-14·CVSS 1.7
CVE-2025-53643 [LOW] CVE-2025-53643 python-aiohttp-oauthlib: AIOHTTP HTTP Request/Response Smuggling [fedora-41]
CVE-2025-53643 python-aiohttp-oauthlib: AIOHTTP HTTP Request/Response Smuggling [fedora-41]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
A quick check does suggest that python-aiohttp-oauthlib is not affected by this specific issue.
I don't have access to the documents referenced by the link - do I need to do something special he
Bugzilla
CVE-2025-53643 python-pytest-aiohttp: AIOHTTP HTTP Request/Response Smuggling [epel-9]
bugzilla·2025-07-14·CVSS 1.7
CVE-2025-53643 [LOW] CVE-2025-53643 python-pytest-aiohttp: AIOHTTP HTTP Request/Response Smuggling [epel-9]
CVE-2025-53643 python-pytest-aiohttp: AIOHTTP HTTP Request/Response Smuggling [epel-9]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component.
Bugzilla
CVE-2025-53643 python-aiohttp: AIOHTTP HTTP Request/Response Smuggling [fedora-42]
bugzilla·2025-07-14·CVSS 1.7
CVE-2025-53643 [LOW] CVE-2025-53643 python-aiohttp: AIOHTTP HTTP Request/Response Smuggling [fedora-42]
CVE-2025-53643 python-aiohttp: AIOHTTP HTTP Request/Response Smuggling [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug repor
Bugzilla
CVE-2025-53643 aiohttp: AIOHTTP HTTP Request/Response Smuggling
bugzilla·2025-07-14·CVSS 1.7
CVE-2025-53643 [LOW] CVE-2025-53643 aiohttp: AIOHTTP HTTP Request/Response Smuggling
CVE-2025-53643 aiohttp: AIOHTTP HTTP Request/Response Smuggling
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability due to not parsing trailer sections of an HTTP request. If a pure Python version of aiohttp is installed (i.e. without the usual C extensions) or AIOHTTP_NO_EXTENSIONS is enabled, then an attacker may be able to execute a request smuggling attack to bypass certain firewalls or proxy protections. Version 3.12.14 contains a patch for this issue.
Discussion:
This issue has been addressed in the following products:
Red Hat Ansible Automation Platform 2.6 for RHEL 9
Red Hat Ansible Automation Platform 2.6 for RHEL 10
Via RHSA-2026:1249 https://access.redh
Bugzilla
CVE-2025-53643 python-aiohttp-sse-client: AIOHTTP HTTP Request/Response Smuggling [fedora-42]
bugzilla·2025-07-14·CVSS 1.7
CVE-2025-53643 [LOW] CVE-2025-53643 python-aiohttp-sse-client: AIOHTTP HTTP Request/Response Smuggling [fedora-42]
CVE-2025-53643 python-aiohttp-sse-client: AIOHTTP HTTP Request/Response Smuggling [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close al
Bugzilla
CVE-2025-53643 python-pytest-aiohttp: AIOHTTP HTTP Request/Response Smuggling [fedora-42]
bugzilla·2025-07-14·CVSS 1.7
CVE-2025-53643 [LOW] CVE-2025-53643 python-pytest-aiohttp: AIOHTTP HTTP Request/Response Smuggling [fedora-42]
CVE-2025-53643 python-pytest-aiohttp: AIOHTTP HTTP Request/Response Smuggling [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bu
Bugzilla
CVE-2025-53643 python-pytest-aiohttp: AIOHTTP HTTP Request/Response Smuggling [epel-8]
bugzilla·2025-07-14·CVSS 1.7
CVE-2025-53643 [LOW] CVE-2025-53643 python-pytest-aiohttp: AIOHTTP HTTP Request/Response Smuggling [epel-8]
CVE-2025-53643 python-pytest-aiohttp: AIOHTTP HTTP Request/Response Smuggling [epel-8]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component.
2025-07-14
Published