#VU120990 Improper handling of highly compressed data in aiohttp - CVE-2025-69223
Published: January 6, 2026
aiohttp
aio-libs
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the application does not properly handle highly compressed data within the auto_decompress feature. A remote attacker can send a specially crafted compressed HTTP request to the server and consume all available memory resources.