AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components. This issue is fixed in version 3.13.3.
Cite this page
CVE-2025-69226. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2025-69226
Use CWE-22, Aiohttp vendor hub and Aiohttp product page to widen CVE-2025-69226 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-22815, CVE-2026-34516 and CVE-2026-34515 for nearby disclosures in the same product family.