CVE-2026-54277Patch(aiohttp / aiohttp)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch aiohttp aiohttp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypass the max_line_size check in parts of an HTTP request in the C parser. If using the optimised C parser (the default in pre-built wheels), then an attacker may be able to send oversized lines through the HTTP parser and use an excessive amount of memory, potentially leading to DoS. This vulnerability is fixed in 3.14.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aiohttp

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
aiohttp

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-14: 2Patch / Workaround · 2026-08-14: 2Technical Details · 2026-08-14: 108-14
Signal classification1 categories
Patch
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Trail of Bits@trailofbits
    Patch

    PATCH THE PLANET BUG SPOTLIGHT: We found a medium-severity bug in aiohttp, Python's HTTP engine that had 600M+ downloads last month. Denys Pakizh caught oversized requests dodging its size limits. Now patched. CVE-2026-54277 in the dashboard: https://trailofbits.com/patch-the-planet/dashboard

    Post summary

    A medium‑severity bug in aiohttp that allows oversized requests to bypass size limits was discovered and has been patched, with the CVE listed on the Patch The Planet dashboard.

    37136125.1K
    39.6K followersView on X
  • ZeroDayDev@ZeroDayDevApp
    Patch

    Trail of Bits found a medium-severity bug in aiohttp, Python's HTTP engine with 600M+ downloads last month. The library let oversized requests slip past its size limits. CVE-2026-54277 is now patched. aiohttp powers everything from scraping tools to production APIs. A bypass on a request size check is the kind of thing that sits unnoticed until someone chains it with a deserialization gadget or memory exhaustion vector. #infosec #cybersecurity

    Post summary

    Trail of Bits disclosed a medium‑severity bug in aiohttp allowing oversized requests to slip past size limits, which is now patched. No active exploitation or PoC details are provided.

    1001051
    92 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appaiohttpaiohttp---

Explore more