PT-2026-49592 · Pypi · Aiohttp

Published

2026-06-15

·

Updated

2026-06-15

·

CVE-2026-54278

CVSS v4.0

6.6

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U

Summary

During cleanup it is possible for a compressed request body to be decompressed into memory in one chunk.

Impact

An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case).

Workaround

Disable compression if unable to upgrade.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-54278
GHSA-G3CQ-J2XW-WF74

Affected Products

Aiohttp