Launch Week Day 1: Announcing Security Design Review
UNKNOWN PyPI

AIOHTTP vulnerable to brute-force leak of internal static file path components

GHSA-54jq-c3m8-4m76 · CVE-2025-69226

Published · Modified

Description

Summary

Path normalization for static files prevents path traversal, but opens up the ability for an attacker to ascertain the
existence of absolute path components.

Impact

If an application uses web.static() (not recommended for production deployments), it may be possible for an attacker to ascertain the existence of path components.


Patch: https://github.com/aio-libs/aiohttp/commit/f2a86fd5ac0383000d1715afddfa704413f0711e

Ready to move

Start Securing

Free, no credit card | First findings in minutes