Skip to content

Cookie Parser Warning Storm

Low
Dreamsorcerer published GHSA-fh55-r93g-j68g Jan 5, 2026

Package

pip aiohttp (pip)

Affected versions

<=3.13.2

Patched versions

3.13.3

Description

Summary

Reading multiple invalid cookies can lead to a logging storm.

Impact

If the cookies attribute is accessed in an application, then an attacker may be able to trigger a storm of warning-level logs using a specially crafted Cookie header.


Patch: 64629a0

Severity

Low

CVE ID

CVE-2025-69230

Weaknesses

No CWEs

Credits