Memory Decompression Vulnerability in AIOHTTP Framework by aio-libs
CVE-2026-54278

6.6MEDIUM

Key Information:

Vendor

Aio-libs

Status
Vendor
CVE Published:
22 June 2026

What is CVE-2026-54278?

A significant vulnerability has been identified in the AIOHTTP framework, where improper handling of compressed request bodies can lead to memory issues during cleanup. An attacker could exploit this flaw by sending a specially crafted compressed payload that, when decompressed, could overwhelm the system's memory. This scenario resembles a zip bomb attack, which may ultimately lead to denial of service. The issue has been resolved in version 3.14.1, making it crucial for users to upgrade to this version to ensure system integrity.

Affected Version(s)

aiohttp < 3.14.1

References

CVSS V4

Score:
6.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.