CVE-2026-54274
HIGHAIOHTTP: Incomplete websocket frame payloads bypass memory limits
Title source: cnaDescription
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual size limits on memory use. This vulnerability is fixed in 3.14.1.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/aio-libs/aiohttp/security/advisories/GHSA-xcgm-r5h9-7989
X_Refsource_Misc x_refsource_misc
https://github.com/aio-libs/aiohttp/commit/14b6ee851fb16ec199acb950de0c82d476799e7d
Scores
CVSS v3
7.5
EPSS
0.0031
EPSS Percentile
22.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-770
Status
published
Products (2)
aio-libs/aiohttp
< 3.14.1
aiohttp/aiohttp
< 3.14.1
Published
Jun 22, 2026
Tracked Since
Jun 22, 2026