PatchSiren

aio-libs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH aio-libs CVE published 2026-08-03

CVE-2026-69244

CVE-2026-69244 AIOHTTP Denial of Service Vulnerability. AIOHTTP, an asynchronous HTTP client/server framework for asyncio and Python, is vulnerable to a denial of service (DoS) due to an out-of-bounds heap read in the C response parser. This issue allows for a potential DoS in the client when building an error message for a malformed response. The vulnerability is fixed in version 3.14.3. Defenders and de [truncated]

MEDIUM aio-libs CVE published 2026-06-22

CVE-2026-54278

CVE-2026-54278 is a medium-severity vulnerability in AIOHTTP, a Python asynchronous HTTP client/server framework. The issue allows for a potential denial of service (DoS) via decompression of a compressed request body into memory. This vulnerability, described as a 'zip bomb edge case,' can be exploited under specific conditions. The vulnerability was published on June 22, 2026, and patched in version 3.1 [truncated]

MEDIUM aio-libs CVE published 2026-06-22

CVE-2026-54274

CVE-2026-54274 is a vulnerability in the AIOHTTP asynchronous HTTP client/server framework for asyncio and Python. An attacker can bypass the usual size limits on memory use by sending large incomplete WebSocket frame payloads. The vulnerability was fixed in version 3.14.1. This issue has a CVSS score of 6.6 and a severity of MEDIUM. The CVE was published on 2026-06-22T18:16:45.877Z and modified on 2026-0 [truncated]

LOW aio-libs CVE published 2026-01-06

CVE-2025-69230

CVE-2025-69230 is a vulnerability in the AIOHTTP framework that can lead to a logging storm when reading multiple invalid cookies. This issue is fixed in version 3.13.3. The vulnerability allows an attacker to trigger a storm of warning-level logs using a specially crafted Cookie header. Defenders should assess exposure and prioritize upgrading to version 3.13.3 or later to prevent potential logging storm [truncated]