Bug 2510825 (CVE-2026-69244)

Summary: CVE-2026-69244 aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: alinfoot, anpicker, anthomas, aprice, bbrownin, brasmith, cahl, cmyers, cochase, dfreiber, dnakabaa, dranck, drow, dschmidt, dtrifiro, ebourniv, ehelms, ggainey, gtanzill, hasun, ilpinto, jburrell, jbuscemi, jdobes, jfula, jlanda, jmitchel, jowilson, jpasqual, jsamir, juwatts, jwong, kaycoth, kshier, lbrazdil, lcouzens, lgallett, ljawale, ltomasbo, mbarnett, mdellweg, mhulan, mminar, msilmser, nmoumoul, nyancey, oezr, omaciel, ometelka, orabin, osousa, pakotvan, pcreech, ptisnovs, rbiba, rbryant, rchan, rjohnson, sbunciak, simaishi, smallamp, sskracic, stcannon, sthirugn, syedriko, teagle, tmalecek, tpfromme, ttakamiy, vkumar, weaton, xdharmai, yguenane, ykashtan, zzhou
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in AIOHTTP, an asynchronous HTTP client/server framework. This vulnerability involves an out-of-bounds heap read in the C response parser when processing malformed HTTP responses. An attacker operating a malicious server, or even an accidental malformed response, could exploit this to trigger a Denial of Service (DoS) in the client application, making it unavailable.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2519528, 2519529    
Bug Blocks:    

Description OSIDB Bzimport 2026-08-03 22:03:09 UTC
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response. An attacker controlled server, or possibly an accidental response, could trigger a DoS in the client. The vulnerable path was error message construction in aiohttp/_http_parser.pyx, where an llhttp error-position pointer was used to build a snippet for malformed chunked responses and malformed request or response bytes at the buffer end. This issue is fixed in version 3.14.3.

Comment 4 errata-xmlrpc 2026-08-24 16:26:10 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.5 for RHEL 9
  Red Hat Ansible Automation Platform 2.5 for RHEL 8

Via RHSA-2026:59135 https://access.redhat.com/errata/RHSA-2026:59135

Comment 5 errata-xmlrpc 2026-08-24 16:27:10 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.6 for RHEL 9
  Red Hat Ansible Automation Platform 2.6 for RHEL 10

Via RHSA-2026:59136 https://access.redhat.com/errata/RHSA-2026:59136

Comment 6 errata-xmlrpc 2026-09-03 22:01:59 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.18 for RHEL 9

Via RHSA-2026:63386 https://access.redhat.com/errata/RHSA-2026:63386

Comment 7 errata-xmlrpc 2026-09-03 22:57:27 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.17 for RHEL 9

Via RHSA-2026:63387 https://access.redhat.com/errata/RHSA-2026:63387

Comment 8 errata-xmlrpc 2026-09-03 22:58:03 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.16 for RHEL 8
  Red Hat Satellite 6.16 for RHEL 9

Via RHSA-2026:63327 https://access.redhat.com/errata/RHSA-2026:63327