Inconsistent interpretation of HTTP requests in aiohttp - CVE-2025-53643

 

Inconsistent interpretation of HTTP requests in aiohttp - CVE-2025-53643

Published: July 18, 2025


Vulnerability identifier: #VU113069
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2025-53643
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.

The vulnerability exists due to not parsing trailer sections of an HTTP request. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.

Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.


Affected software

aiohttp
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Fedora
Public Cloud Module
Python 3 Module
openSUSE Leap
IBM Fusion HCI
Ansible Automation Platform
Red Hat OpenShift AI (RHOAI)
OpenShift Service Mesh
Guardium Data Security Center (GDSC)
Oracle Communications Operations Monitor
Maximo Application Suite Ai Service
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
Oracle Utilities Live Energy Connect
Splunk Enterprise
Siebel CRM Cloud Applications
python3.11-galaxy-importer (Red Hat package)
automation-eda-controller (Red Hat package)
receptor (Red Hat package)
python3.11-botocore (Red Hat package)
automation-gateway (Red Hat package)
python3.11-urllib3 (Red Hat package)
ansible-automation-platform-installer (Red Hat package)
automation-platform-ui (Red Hat package)
python3.11-django-ansible-base (Red Hat package)
ansible-core (Red Hat package)
python3.11-requests (Red Hat package)
python-aiohttp-debugsource
python3-aiohttp-debuginfo
python3-aiohttp
python311-aiohttp
python311-aiohttp-debuginfo
python-aiohttp
python3.11-pulpcore (Red Hat package)
python3.11-django (Red Hat package)
python-django (Red Hat package)
automation-controller (Red Hat package)
automation-hub (Red Hat package)
python3.11-galaxy-ng (Red Hat package)
python3.11-protobuf (Red Hat package)
ansible-lint (Red Hat package)
ansible-dev-tools (Red Hat package)
ansible-navigator (Red Hat package)

How to mitigate CVE-2025-53643

Install updates from vendor's website.

aiohttp - update to 3.12.14
IBM Fusion HCI - update to 2.11.0
OpenShift Service Mesh - addressed in versions 3.0.7, 3.1.4
Guardium Data Security Center (GDSC) - update to 3.8.5
Splunk Enterprise - addressed in versions 9.2.12, 9.3.9, 9.4.8, 10.0.3
Maximo Application Suite Ai Service - update to 9.1.3
python3.11-galaxy-importer (Red Hat package) - addressed in versions 0.4.37-2.el8ap, 0.4.37-2.el9ap
automation-eda-controller (Red Hat package) - update to 1.2.4-1.el9ap
receptor (Red Hat package) - addressed in versions 1.6.3-1.el8ap, 1.6.3-1.el9ap, 1.6.3-2.el9ap, 1.6.3-2.el10ap
python3.11-botocore (Red Hat package) - addressed in versions 1.34.162-1.el8ap, 1.34.162-1.el9ap
Ansible Automation Platform - addressed in versions 2.5, 2.6
automation-gateway (Red Hat package) - addressed in versions 2.5.20260121-1.el8ap, 2.5.20260121-1.el9ap, 2.6.20260121-1.el9ap
python3.11-urllib3 (Red Hat package) - addressed in versions 2.6.3-1.el8ap, 2.6.3-1.el9ap
ansible-automation-platform-installer (Red Hat package) - update to 2.6-4.el9ap
automation-platform-ui (Red Hat package) - update to 2.6.5-1.el9ap
python3.11-django-ansible-base (Red Hat package) - update to 2.6.20260121-1.el9ap
ansible-core (Red Hat package) - addressed in versions 2.16.15-1.el8ap, 2.16.15-1.el9ap, 2.16.15-2.el10ap
Red Hat OpenShift AI (RHOAI) - addressed in versions 2.22.3, 2.25.1
python3.11-requests (Red Hat package) - addressed in versions 2.31.0-3.el8ap, 2.31.0-3.el9ap
python-aiohttp-debugsource - addressed in versions 3.6.0-150100.3.27.1, 3.9.3-150400.10.33.1
python3-aiohttp-debuginfo - update to 3.6.0-150100.3.27.1
python3-aiohttp - update to 3.6.0-150100.3.27.1
python311-aiohttp - update to 3.9.3-150400.10.33.1
python311-aiohttp-debuginfo - update to 3.9.3-150400.10.33.1
python-aiohttp - addressed in versions 3.11.18-4.el10_1, 3.11.18-4.el10_2
python3.11-pulpcore (Red Hat package) - update to 3.49.49-1.el9ap
python3.11-django (Red Hat package) - addressed in versions 4.2.27-1.el8ap, 4.2.27-1.el9ap, 4.2.27-2.el9ap
python-django (Red Hat package) - update to 4.2.27-2.el10ap
automation-controller (Red Hat package) - addressed in versions 4.6.25-1.el8ap, 4.6.25-1.el9ap, 4.7.8-1.el9ap
automation-hub (Red Hat package) - addressed in versions 4.10.11-1.el8ap, 4.10.11-1.el9ap, 4.11.5-1.el9ap
python3.11-galaxy-ng (Red Hat package) - addressed in versions 4.10.11-2.el8ap, 4.10.11-2.el9ap, 4.11.5-1.el9ap
python3.11-protobuf (Red Hat package) - update to 4.25.8-1.el9ap
watsonx Assistant Cartridge - update to 5.3.0
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.3.0
ansible-lint (Red Hat package) - addressed in versions 26.1.0-1.el8ap, 26.1.0-1.el9ap, 26.1.0-2.el9ap, 26.1.0-2.el10ap
ansible-dev-tools (Red Hat package) - addressed in versions 26.1.0-1.el8ap, 26.1.0-1.el9ap, 26.1.0-2.el9ap, 26.1.0-2.el10ap
ansible-navigator (Red Hat package) - addressed in versions 26.1.1-1.el8ap, 26.1.1-1.el9ap, 26.1.1-2.el9ap, 26.1.1-2.el10ap

External References

Related Security Bulletins