PT-2026-49592 · Pypi · Aiohttp

·

CVE-2026-54278

·

Published

2026-06-15

·

Updated

2026-07-23

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions AIOHTTP versions prior to 3.14.1
Description During cleanup, a compressed request body can be decompressed into memory in a single chunk. An attacker may send a compressed payload in specific situations that could be decompressed into memory, potentially leading to a Denial of Service (DoS) via a zip bomb, which is a malicious archive designed to crash or freeze the system by expanding to an enormous size upon decompression.
Recommendations Update to version 3.14.1. Disable compression as a temporary workaround if an upgrade is not possible.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54278
ECHO-2791-8592-919C
GHSA-G3CQ-J2XW-WF74
OESA-2026-2838
OESA-2026-2839
OPENSUSE-SU-2026:21372-1
PYSEC-2026-2111
SUSE-SU-2026:22819-1
SUSE-SU-2026:3207-1
SUSE-SU-2026:3208-1

Affected Products

Aiohttp