Inconsistent interpretation of HTTP requests in aiohttp - CVE-2025-53643
Published: July 18, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.
The vulnerability exists due to not parsing trailer sections of an HTTP request. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.
Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.
Affected software
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Fedora
Public Cloud Module
Python 3 Module
openSUSE Leap
IBM Fusion HCI
Ansible Automation Platform
Red Hat OpenShift AI (RHOAI)
OpenShift Service Mesh
Guardium Data Security Center (GDSC)
Oracle Communications Operations Monitor
Maximo Application Suite Ai Service
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
Oracle Utilities Live Energy Connect
Splunk Enterprise
Siebel CRM Cloud Applications
python3.11-galaxy-importer (Red Hat package)
automation-eda-controller (Red Hat package)
receptor (Red Hat package)
python3.11-botocore (Red Hat package)
automation-gateway (Red Hat package)
python3.11-urllib3 (Red Hat package)
ansible-automation-platform-installer (Red Hat package)
automation-platform-ui (Red Hat package)
python3.11-django-ansible-base (Red Hat package)
ansible-core (Red Hat package)
python3.11-requests (Red Hat package)
python-aiohttp-debugsource
python3-aiohttp-debuginfo
python3-aiohttp
python311-aiohttp
python311-aiohttp-debuginfo
python-aiohttp
python3.11-pulpcore (Red Hat package)
python3.11-django (Red Hat package)
python-django (Red Hat package)
automation-controller (Red Hat package)
automation-hub (Red Hat package)
python3.11-galaxy-ng (Red Hat package)
python3.11-protobuf (Red Hat package)
ansible-lint (Red Hat package)
ansible-dev-tools (Red Hat package)
ansible-navigator (Red Hat package)
How to mitigate CVE-2025-53643
IBM Fusion HCI - update to 2.11.0
OpenShift Service Mesh - addressed in versions 3.0.7, 3.1.4
Guardium Data Security Center (GDSC) - update to 3.8.5
Splunk Enterprise - addressed in versions 9.2.12, 9.3.9, 9.4.8, 10.0.3
Maximo Application Suite Ai Service - update to 9.1.3
python3.11-galaxy-importer (Red Hat package) - addressed in versions 0.4.37-2.el8ap, 0.4.37-2.el9ap
automation-eda-controller (Red Hat package) - update to 1.2.4-1.el9ap
receptor (Red Hat package) - addressed in versions 1.6.3-1.el8ap, 1.6.3-1.el9ap, 1.6.3-2.el9ap, 1.6.3-2.el10ap
python3.11-botocore (Red Hat package) - addressed in versions 1.34.162-1.el8ap, 1.34.162-1.el9ap
Ansible Automation Platform - addressed in versions 2.5, 2.6
automation-gateway (Red Hat package) - addressed in versions 2.5.20260121-1.el8ap, 2.5.20260121-1.el9ap, 2.6.20260121-1.el9ap
python3.11-urllib3 (Red Hat package) - addressed in versions 2.6.3-1.el8ap, 2.6.3-1.el9ap
ansible-automation-platform-installer (Red Hat package) - update to 2.6-4.el9ap
automation-platform-ui (Red Hat package) - update to 2.6.5-1.el9ap
python3.11-django-ansible-base (Red Hat package) - update to 2.6.20260121-1.el9ap
ansible-core (Red Hat package) - addressed in versions 2.16.15-1.el8ap, 2.16.15-1.el9ap, 2.16.15-2.el10ap
Red Hat OpenShift AI (RHOAI) - addressed in versions 2.22.3, 2.25.1
python3.11-requests (Red Hat package) - addressed in versions 2.31.0-3.el8ap, 2.31.0-3.el9ap
python-aiohttp-debugsource - addressed in versions 3.6.0-150100.3.27.1, 3.9.3-150400.10.33.1
python3-aiohttp-debuginfo - update to 3.6.0-150100.3.27.1
python3-aiohttp - update to 3.6.0-150100.3.27.1
python311-aiohttp - update to 3.9.3-150400.10.33.1
python311-aiohttp-debuginfo - update to 3.9.3-150400.10.33.1
python-aiohttp - addressed in versions 3.11.18-4.el10_1, 3.11.18-4.el10_2
python3.11-pulpcore (Red Hat package) - update to 3.49.49-1.el9ap
python3.11-django (Red Hat package) - addressed in versions 4.2.27-1.el8ap, 4.2.27-1.el9ap, 4.2.27-2.el9ap
python-django (Red Hat package) - update to 4.2.27-2.el10ap
automation-controller (Red Hat package) - addressed in versions 4.6.25-1.el8ap, 4.6.25-1.el9ap, 4.7.8-1.el9ap
automation-hub (Red Hat package) - addressed in versions 4.10.11-1.el8ap, 4.10.11-1.el9ap, 4.11.5-1.el9ap
python3.11-galaxy-ng (Red Hat package) - addressed in versions 4.10.11-2.el8ap, 4.10.11-2.el9ap, 4.11.5-1.el9ap
python3.11-protobuf (Red Hat package) - update to 4.25.8-1.el9ap
watsonx Assistant Cartridge - update to 5.3.0
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.3.0
ansible-lint (Red Hat package) - addressed in versions 26.1.0-1.el8ap, 26.1.0-1.el9ap, 26.1.0-2.el9ap, 26.1.0-2.el10ap
ansible-dev-tools (Red Hat package) - addressed in versions 26.1.0-1.el8ap, 26.1.0-1.el9ap, 26.1.0-2.el9ap, 26.1.0-2.el10ap
ansible-navigator (Red Hat package) - addressed in versions 26.1.1-1.el8ap, 26.1.1-1.el9ap, 26.1.1-2.el9ap, 26.1.1-2.el10ap
External References
Related Security Bulletins
- Inconsistent interpretation of HTTP requests in aiohttp
- SUSE update for python-aiohttp
- SUSE update for python-aiohttp
- Multiple vulnerabilities in IBM Fusion
- IBM Maximo AI Service update for AIOHTTP
- Fedora EPEL 10.2 update for python-aiohttp
- Fedora EPEL 10.1 update for python-aiohttp
- Multiple vulnerabilities in Oracle Communications Operations Monitor
- Multiple vulnerabilities in IBM Guardium Data Security Center
- Multiple vulnerabilities in Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Service Mesh update for aiohttp
- Multiple vulnerabilities in Red Hat OpenShift AI (RHOAI)
- IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge update for AIOHTTP
- Multiple vulnerabilities in Siebel CRM Cloud Applications
- Multiple vulnerabilities in Ansible Automation Platform 2.6 packages
- Multiple vulnerabilities in Ansible Automation Platform 2.5 packages
- Splunk Enterprise Security update for third-party components
- Inconsistent interpretation of HTTP requests in Oracle Utilities Live Energy Connect