Skip to content

Unicode match groups in regexes for ASCII protocol elements

Low
Dreamsorcerer published GHSA-mqqc-3gqh-h2x8 Jan 5, 2026

Package

pip aiohttp (pip)

Affected versions

<=3.13.2

Patched versions

3.13.3

Description

Summary

The parser allows non-ASCII decimals to be present in the Range header.

Impact

There is no known impact, but there is the possibility that there's a method to exploit a request smuggling vulnerability.


Patch: c7b7a04

Severity

Low

CVE ID

CVE-2025-69225

Weaknesses

No CWEs

Credits