Resource management error in aiohttp - CVE-2025-69230
Published: January 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the application when reading invalid cookie attributes. A remote attacker can send specially crafted requests to the application and produce a huge amount of log entries, leading to a denial of service condition.
Affected software
Fusion Content-Aware Storage
watsonx Code Assistant On Prem
Maximo Application Suite - Predict Component
Robotic Process Automation for Cloud Pak
IBM Fusion HCI
Splunk Enterprise
Anolis OS
python3-aiohttp+speedups
python3-aiohttp
How to mitigate CVE-2025-69230
Fusion Content-Aware Storage - update to 1.1.2
IBM Fusion HCI - update to 2.12.1
watsonx Code Assistant On Prem - update to 5.3.1
Maximo Application Suite - Predict Component - addressed in versions 9.0.17, 9.1.10, 9.2.1
Splunk Enterprise - addressed in versions 9.3.10, 9.4.9, 10.0.4, 10.2.1
Robotic Process Automation for Cloud Pak - addressed in versions 23.0.20.6, 30.0.2
python3-aiohttp+speedups - update to 3.13.3-1
python3-aiohttp - update to 3.13.3-1
External References
Related Security Bulletins
- Multiple vulnerabilities in aiohttp
- Multiple vulnerabilities in IBM watsonx Code Assistant On Prem
- Anolis OS update for python-aiohttp
- Multiple vulnerabilities in Splunk Enterprise
- Multiple vulnerabilities in IBM Fusion Content-Aware Storage
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in IBM Maximo Application Suite - Predict Component