StackRadar

CVE-2025-53643

High

Advisory

Published 14 Jul 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
110
of 17,781 indexed, latest versions
Container images
113
deployed by those charts
Fix available
1 of 2
affected packages

AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections

Carried by container images the latest versions of 110 of 17,781 indexed charts deploy, on 113 images.

Affected packageAffected versionsFixed inImages
python-aiohttpdeb3.8.4-1, 3.11.16-1+deb13u1no fix listed2
aiohttppypi3.4.4, 3.5.4, 3.6.2, 3.7.1+26 more3.12.14113
OSV records
DEBIAN-CVE-2025-53643GHSA-9548-qrrj-x5pj
Also known as
PYSEC-2026-1104

Charts affected

110 by stars
ChartLatestAffected imagesRadar Score
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-53643.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
aiohttp@3.10.5
3.12.14

Open the chart page →

5,198
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-53643.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
aiohttp@3.10.5
3.12.14

Open the chart page →

9,616
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-53643.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
aiohttp@3.10.5
3.12.14

Open the chart page →

4,377
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-53643.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
aiohttp@3.10.5
3.12.14

Open the chart page →

5,350
kasa-exporterth-chartsVerified publisher0.1.01 of 1See more

kasa-exporter th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-53643.

Container imageDigestPackageFixed in
thelande/kasa_exporter:v0.2.3a1fdb8baa152
aiohttp@3.9.5
3.12.14

Open the chart page →

1,515
traefik-external-dns-operatortraefik-external-dns-operator1.0.11 of 1See more

traefik-external-dns-operator traefik-external-dns-operator 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-53643.

Container imageDigestPackageFixed in
ybucci/traefik-external-dns-operator:1.0.0f1fcc7c8d9fd
aiohttp@3.11.14
3.12.14

Open the chart page →

1,083
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2025-53643.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
aiohttp@3.8.1
3.12.14

Open the chart page →

8,607
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2025-53643.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
aiohttp@3.7.4
3.12.14

Open the chart page →

11,119
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2025-53643.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
aiohttp@3.8.1
3.12.14

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-53643.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
aiohttp@3.8.1
3.12.14

Open the chart page →

1,636

Container images carrying it

113 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
aiohttp@3.12.13
3.12.14
1
ghcr.io/serenita-org/vero:v0.8.3e5a7ec714acc
aiohttp@3.10.10
3.12.14
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
aiohttp@3.8.3
3.12.14
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
aiohttp@3.8.3
3.12.14
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
aiohttp@3.10.11
3.12.14
1
ghcr.io/tauffer-consulting/domino-rest:latest8bf880fe8c73
aiohttp@3.8.3
3.12.14
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
aiohttp@3.11.11
3.12.14
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
aiohttp@3.10.10
3.12.14
1
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
aiohttp@3.11.11
3.12.14
1
quay.io/evl.ms/argocd-exporter:0.0.136ea8f34aa6b
aiohttp@3.7.4.post0
3.12.14
1
quay.io/jupyterhub/k8s-hub:3.2.12528c6e57587
aiohttp@3.9.1
3.12.14
1
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
aiohttp@3.8.1
3.12.14
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
aiohttp@3.9.5
3.12.14
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.