Security Vulnerability in AIOHTTP Framework by aio-libs
CVE-2026-54277

6.6MEDIUM

Key Information:

Vendor

Aio-libs

Status
Vendor
CVE Published:
22 June 2026

What is CVE-2026-54277?

AIOHTTP, a popular asynchronous HTTP client/server framework for Python, has a vulnerability that allows attackers to bypass the max_line_size check in the C parser prior to version 3.14.1. This flaw may enable attackers to send excessively long lines through the HTTP parser, exploiting memory management and leading to potential denial-of-service (DoS) conditions. Users are strongly advised to upgrade to version 3.14.1 or later to mitigate this risk effectively. For more details, refer to the security advisory and commit documentation linked.

Affected Version(s)

aiohttp < 3.14.1

References

CVSS V4

Score:
6.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.