PT-2026-49588 · Pypi · Aiohttp

·

CVE-2026-54274

·

Published

2026-06-15

·

Updated

2026-07-23

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions AIOHTTP versions prior to 3.14.1
Description An issue exists in the asynchronous HTTP client/server framework where an attacker can send large incomplete websocket frame payloads. This allows the attacker to bypass standard memory use size limits, potentially leading to a Denial of Service (DoS) attack through excessive memory consumption if the web application utilizes WebSocket endpoints.
Recommendations Update to version 3.14.1.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54274
ECHO-E352-AA77-0D12
GHSA-XCGM-R5H9-7989
OESA-2026-2838
OESA-2026-2839
OPENSUSE-SU-2026:21372-1
PYSEC-2026-2108
SUSE-SU-2026:22819-1
SUSE-SU-2026:3207-1
SUSE-SU-2026:3208-1

Affected Products

Aiohttp