CVE-2026-54278: Aiohttp

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1.

Affected products

  • Aiohttp Aiohttp: before 3.14.1 (fixed in 3.14.1)

Published 2026-06-22. Last modified 2026-06-26.