Junglewise Threat Intelligence

CVE-2025-69230: aiohttp logging storm in cookie parsing

CVE-2025-69230 · Severity: medium · CVSS 5.3 · Published 2026-01-06

Technologies: Aio-Libs Aiohttp. Vendors: PyPI.

Executive brief

aiohttp is a Python library for building asynchronous web applications. A specially crafted HTTP Cookie header can trigger excessive warning-level logs in applications that access the cookies attribute, potentially degrading performance and filling log storage. This is resolved in version 3.13.3.

Technical details

The vulnerability is a denial-of-service via logging storm in aiohttp's cookie parser. When an application accesses the cookies attribute of a request and a malformed Cookie header is present, the parser generates repeated warning logs for each invalid cookie, rather than logging once per header. An attacker can craft a Cookie header with multiple invalid entries to flood the application logs. The attack requires network access to send a specially crafted HTTP request to an application using aiohttp. The fix, merged in commit 64629a0, implements per-header logging limits to prevent the storm.

Affected products

  • aio-libs aiohttp <=3.13.2

Timeline

  • 2026-01-06: disclosed
  • 2026-01-05: patched: Fix available in version 3.13.3

References

Related threats