CVE-2026-54278
EUVD-2026-3831522.06.2026, 18:16
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| aiohttp | aiohttp | 𝑥 < 3.14.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
Common Weakness Enumeration