PT-2026-49594 · Pypi · Aiohttp

·

CVE-2026-54280

·

Published

2026-06-15

·

Updated

2026-07-23

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions AIOHTTP versions prior to 3.14.1
Description Payload resources are not closed correctly when a client disconnects during a write operation. If a payload utilizes an open file or other limited resources, an attacker can cause temporary resource starvation until the resources are released by garbage collection.
Recommendations Update to version 3.14.1.

Exploit

Fix

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54280
ECHO-D1AC-9337-96AB
GHSA-9X8Q-7H8H-WCW9
OESA-2026-2838
OESA-2026-2839
OPENSUSE-SU-2026:21372-1
PYSEC-2026-2113
SUSE-SU-2026:22819-1
SUSE-SU-2026:3207-1
SUSE-SU-2026:3208-1

Affected Products

Aiohttp