Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g3cq-j2xw-wf74

Опубликовано: 15 июн. 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.6

Описание

aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup

Summary

During cleanup it is possible for a compressed request body to be decompressed into memory in one chunk.

Impact

An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case).

Workaround

Disable compression if unable to upgrade.


Patch: https://github.com/aio-libs/aiohttp/commit/4f7480e474cccc6a8cc2c92ad3f17a31dedf8232

Пакеты

Наименование

aiohttp

pip
Затронутые версииВерсия исправления

<= 3.14.0

3.14.1

EPSS

Процентиль: 33%
0.00397
Низкий

6.6 Medium

CVSS4

Дефекты

CWE-409

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1.

CVSS3: 5.9
redhat
около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1.

CVSS3: 7.5
nvd
около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1.

CVSS3: 7.5
debian
около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

suse-cvrf
18 дней назад

Security update for python-aiohttp

EPSS

Процентиль: 33%
0.00397
Низкий

6.6 Medium

CVSS4

Дефекты

CWE-409