CVE-2026-54280

HIGH

AIOHTTP: Payload Response Resources Are Not Closed After Mid-Body Disconnect

Title source: cna
STIX 2.1

Description

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar limited resource, then an attacker may be able to cause resource starvation temporarily until garbage collection or similar closes the file. This vulnerability is fixed in 3.14.1.

Scores

CVSS v3 7.5
EPSS 0.0028
EPSS Percentile 20.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-404
Status published
Products (2)
aio-libs/aiohttp < 3.14.1
aiohttp/aiohttp < 3.14.1
Published Jun 22, 2026
Tracked Since Jun 22, 2026