CVE-2026-69244

ADVISORY - github

Summary

Summary

An out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response.

Impact

An attacker controlled server, or possibly an accidental response could trigger a DoS in the client.

Workaround

If unable to upgrade, the Python parser is unaffected and can be used with AIOHTTP_NO_EXTENSIONS=1.


Patch: https://github.com/aio-libs/aiohttp/commit/49f65d54150397892f7bcc4aae887767d51c322d

Common Weakness Enumeration (CWE)

ADVISORY - nist

Out-of-bounds Read

Uncontrolled Resource Consumption

Use After Free

ADVISORY - github

Out-of-bounds Read

Uncontrolled Resource Consumption

Use After Free


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in