CVE-2026-69244 AIOHTTP Denial of Service Vulnerability. AIOHTTP, an asynchronous HTTP client/server framework for asyncio and Python, is vulnerable to a denial of service (DoS) due to an out-of-bounds heap read in the C response parser. This issue allows for a potential DoS in the client when building an error message for a malformed response. The vulnerability is fixed in version 3.14.3. Defenders and de [truncated]
CVE-2026-54278 is a medium-severity vulnerability in AIOHTTP, a Python asynchronous HTTP client/server framework. The issue allows for a potential denial of service (DoS) via decompression of a compressed request body into memory. This vulnerability, described as a 'zip bomb edge case,' can be exploited under specific conditions. The vulnerability was published on June 22, 2026, and patched in version 3.1 [truncated]
CVE-2026-54274 is a vulnerability in the AIOHTTP asynchronous HTTP client/server framework for asyncio and Python. An attacker can bypass the usual size limits on memory use by sending large incomplete WebSocket frame payloads. The vulnerability was fixed in version 3.14.1. This issue has a CVSS score of 6.6 and a severity of MEDIUM. The CVE was published on 2026-06-22T18:16:45.877Z and modified on 2026-0 [truncated]
CVE-2025-69230 is a vulnerability in the AIOHTTP framework that can lead to a logging storm when reading multiple invalid cookies. This issue is fixed in version 3.13.3. The vulnerability allows an attacker to trigger a storm of warning-level logs using a specially crafted Cookie header. Defenders should assess exposure and prioritize upgrading to version 3.13.3 or later to prevent potential logging storm [truncated]