Количество 8
Количество 8
CVE-2026-54278
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1.
CVE-2026-54278
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1.
CVE-2026-54278
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1.
CVE-2026-54278
AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...
GHSA-g3cq-j2xw-wf74
aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup
openSUSE-SU-2026:21372-1
Security update for python-aiohttp
SUSE-SU-2026:3208-1
Security update for python-aiohttp
SUSE-SU-2026:3207-1
Security update for python-aiohttp
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-54278 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-54278 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1. | CVSS3: 5.9 | 0% Низкий | около 1 месяца назад | |
CVE-2026-54278 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-54278 AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ... | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
GHSA-g3cq-j2xw-wf74 aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup | 0% Низкий | около 2 месяцев назад | ||
openSUSE-SU-2026:21372-1 Security update for python-aiohttp | 18 дней назад | |||
SUSE-SU-2026:3208-1 Security update for python-aiohttp | 12 дней назад | |||
SUSE-SU-2026:3207-1 Security update for python-aiohttp | 12 дней назад |
Уязвимостей на страницу