Memory Exhaustion Vulnerability in AIOHTTP by aio-libs
CVE-2026-54273

6.6MEDIUM

Key Information:

Vendor

Aio-libs

Status
Vendor
CVE Published:
22 June 2026

What is CVE-2026-54273?

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python that was found to have a vulnerability allowing an attacker to exploit unlimited pipelined requests prior to version 3.14.1. This lack of limits on queued requests could potentially lead to significant memory exhaustion, resulting in denial of service (DoS) conditions. It is crucial for users of versions prior to 3.14.1 to upgrade to secure their applications against such exploits.

Affected Version(s)

aiohttp < 3.14.1

References

CVSS V4

Score:
6.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.