Back to CVE List

CVE-2026-54280

LOW SEVERITY

CVSS Score & Metrics

Base Score
7.5 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Vulnerability Description

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar limited resource, then an attacker may be able to cause resource starvation temporarily until garbage collection or similar closes the file. This vulnerability is fixed in 3.14.1.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-404
Source
GitHub
Vendor
pip
Product
aiohttp

External References

Discussion (0)

Add Comment

No comments yet. Be the first!