← back
CVE-2026-54273

AIOHTTP: HTTP/1 Pipelined Requests Queue Without Limit

CVSS 6.6 MEDIUMEPSS 0.3%CWE-770
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on the number of pipelined requests that could be queued. An attacker may be able to use pipelined requests to use excessive amounts of memory, potentially leading to DoS. This vulnerability is fixed in 3.14.1.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U
Affected products
aio-libs · aiohttp

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →