CVE-2025-53643: AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
(updated )
The Python parser is vulnerable to a request smuggling vulnerability due to not parsing trailer sections of an HTTP request.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-53643 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →