Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-54278

Опубликовано: 22 июн. 2026
Источник: debian
EPSS Низкий

Описание

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-aiohttpfixed3.14.1-1package
python-aiohttpignoredtrixiepackage
python-aiohttpnot-affectedbookwormpackage
python-aiohttpnot-affectedbullseyepackage

Примечания

  • https://github.com/aio-libs/aiohttp/security/advisories/GHSA-g3cq-j2xw-wf74

  • Fixed by: https://github.com/aio-libs/aiohttp/commit/4f7480e474cccc6a8cc2c92ad3f17a31dedf8232 (v3.14.1)

  • Major rewrite in: https://github.com/aio-libs/aiohttp/commit/b502ae655c8788b469dcc832923a85d661719699 (v3.14.0)

EPSS

Процентиль: 33%
0.00397
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1.

CVSS3: 5.9
redhat
около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1.

CVSS3: 7.5
nvd
около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1.

github
около 2 месяцев назад

aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup

suse-cvrf
18 дней назад

Security update for python-aiohttp

EPSS

Процентиль: 33%
0.00397
Низкий