CVE-2026-54278

EUVD-2026-38315
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1.
Data Amplification
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 32.5%
Affected Products (NVD)
VendorProductVersion
aiohttpaiohttp
𝑥
< 3.14.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
python-aiohttp
bookworm
3.8.4-1+deb12u1
fixed
bookworm (security)
3.8.4-1+deb12u1
fixed
bullseye
3.7.4-1
fixed
bullseye (security)
3.7.4-1+deb11u2
fixed
forky
3.14.1-4
fixed
sid
3.14.1-4
fixed
trixie
ignored
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-aiohttp
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
python3-aiohttp
suse enterprise sap 15 SP4
3.6.0-150100.3.38.1
fixed
suse enterprise server 15 SP4
3.6.0-150100.3.38.1
fixed
python311-aiohttp
suse enterprise sap 15 SP4
3.9.3-150400.10.43.1
fixed
suse enterprise server 15 SP4
3.9.3-150400.10.43.1
fixed