Memory Bypass in AIOHTTP Framework for Python
CVE-2026-54274

6.6MEDIUM

Key Information:

Vendor

Aio-libs

Status
Vendor
CVE Published:
22 June 2026

What is CVE-2026-54274?

The AIOHTTP framework, an asynchronous HTTP client/server for Python, has a vulnerability that allows attackers to bypass memory size limits by sending large incomplete websocket frame payloads. This poses a risk of excessive memory consumption, which can lead to denial of service conditions. Users are urged to update to AIOHTTP version 3.14.1 or later, where this issue has been resolved.

Affected Version(s)

aiohttp < 3.14.1

References

CVSS V4

Score:
6.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.