AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual size limits on memory use. This vulnerability is fixed in 3.14.1.
References
| Link | Resource |
|---|---|
| https://github.com/aio-libs/aiohttp/commit/14b6ee851fb16ec199acb950de0c82d476799e7d | Patch |
| https://github.com/aio-libs/aiohttp/security/advisories/GHSA-xcgm-r5h9-7989 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-06-22 18:16
Updated : 2026-06-26 19:37
NVD link : CVE-2026-54274
Mitre link : CVE-2026-54274
CVE.ORG link : CVE-2026-54274
JSON object : View
Products Affected
aiohttp
- aiohttp
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
