PT-2026-49587 · Pypi · Aiohttp

·

CVE-2026-54273

·

Published

2026-06-15

·

Updated

2026-07-23

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions AIOHTTP versions prior to 3.14.1
Description AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. The software lacked a limit on the number of pipelined requests that could be queued. An attacker could exploit this by sending pipelined requests to consume excessive amounts of memory, potentially resulting in a Denial of Service (DoS), which is a condition where a system becomes unavailable to its intended users.
Recommendations Update to version 3.14.1.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54273
ECHO-7903-2043-8947
GHSA-4FVR-RGM6-GQMC
OESA-2026-2838
OESA-2026-2839
OPENSUSE-SU-2026:11097-1
OPENSUSE-SU-2026:21372-1
PYSEC-2026-2107
SUSE-SU-2026:22819-1
SUSE-SU-2026:3207-1
SUSE-SU-2026:3208-1

Affected Products

Aiohttp