CVE-2026-69243 is an HTTP request-smuggling vulnerability in the server-side HTTP parsers of aiohttp versions before 3.14.2. When processing a WebSocket upgrade request containing a body, the parser can switch protocols before receiving the complete request body. Trailing bytes may consequently be interpreted as upgraded-protocol or pipelined data instead of HTTP body data, enabling request smuggling. The vulnerability is fixed in aiohttp 3.14.2.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a real exploit PoC and lab for CVE-2026-69243, an aiohttp request smuggling issue caused by rejected WebSocket upgrade handling. The core exploit sends a single crafted HTTP request where the outer request targets `/ws` with `Connection: Upgrade` and `Upgrade: websocket`, while the body contains a second full HTTP request to `/admin`. On vulnerable aiohttp (<3.14.2), the body is not consumed after upgrade rejection and is reparsed as a pipelined request, creating a frontend/backend desynchronization condition (CWE-444). Structure: the repo contains a polished Rust PoC project under `poc/` (`src/lib.rs` for payload generation/response analysis, `src/main.rs` for CLI, tests and fuzz targets), a standalone Python PoC at repo root (`poc.py`), older/raw attacker scripts under `attacker/scripts/` for phase-based reproduction (`reproduce.rs`, `reproduce.c`, `fase2.rs`, `poc.rs`), a vulnerable aiohttp backend lab app in `backend/app.py`, multiple Nginx proxy configurations in `frontend/*.conf`, Docker orchestration in `docker-compose.yml`, and extensive research notes in `findings/`. Main exploit capabilities: (1) direct backend parser-confusion testing against aiohttp to observe multiple responses on one TCP connection; (2) full proxy-mediated request smuggling through Nginx when upgrade headers are forwarded; (3) blind access-control bypass where Nginx enforces `deny all` on `/admin` for normal requests but the smuggled `/admin` still reaches the backend; (4) optional chunked framing variant to test proxy normalization behavior; and (5) log-based verification/detection support via backend/frontend mismatch analysis. The exploit is operational rather than merely demonstrative: it includes working Rust and Python implementations, Dockerized vulnerable/patched environments, CI parity tests ensuring identical payloads across languages, and integration tests that verify `/admin` appears in backend logs but not in Nginx logs. It is not part of a common exploit framework. The payload is fixed/basic (smuggled `GET /admin`), so maturity is best classified as OPERATIONAL rather than weaponized.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability published on August 3, 2026, with exploits available and a patch published on August 4, 2026. The supplied CVSS vectors describe network-based exploitation with high attack complexity, no required authentication or privileges, and no user interaction. Impact assessments differ: CVSS v3 indicates high confidentiality impact and low integrity and availability impacts, whereas CVSS v4 indicates only low integrity impact. The affected product and underlying flaw are not identified.
An HTTP request-smuggling vulnerability affecting aiohttp's WebSocket upgrade procedure.
An HTTP request-smuggling vulnerability in python3-aiohttp involving its WebSocket upgrade procedure.
An HTTP request-smuggling vulnerability in AIOHTTP associated with WebSocket Upgrade handling.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.