Skip to content

Brute-force leak of internal static file path components

Low
Dreamsorcerer published GHSA-54jq-c3m8-4m76 Jan 5, 2026

Package

pip aiohttp (pip)

Affected versions

<=3.13.2

Patched versions

3.13.3

Description

Summary

Path normalization for static files prevents path traversal, but opens up the ability for an attacker to ascertain the
existence of absolute path components.

Impact

If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components.


Patch: f2a86fd

Severity

Low

CVE ID

CVE-2025-69226

Weaknesses

No CWEs

Credits