CVE-2026-54278·Python vulnerability
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1.
- Severity
- high
- Software
- Python
- Fixed in
- 3.14.1
- Published
- 2026-06-22
Affected versions
Until: 3.14.1
Fixed in: 3.14.1
How to fix this CVE
Update Python's aiohttp library to version 3.14.1 or later to patch a memory exhaustion vulnerability in compressed request body handling. This fix prevents potential denial-of-service attacks that could occur when maliciously crafted compressed payloads are decompressed during request cleanup. Organizations running aiohttp-dependent applications should prioritize this update to eliminate the attack surface.
sudo dnf update python3-aiohttpDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST|PUT requests with Content-Encoding: deflate|gzip headers containing unusually large compressed payloads (>100MB compressed size) that decompress to significantly larger sizes (>1GB uncompressed ratio)WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement WAF rules to limit decompressed request body size to 50MB maximum and enforce Content-Encoding header validation. Block requests where the compression ratio exceeds 100:1 to prevent zip bomb-style attacks against aiohttp handlers.How to check if you are affected
- Run 'python3 -c "import aiohttp; print(aiohttp.__version__)"' to retrieve the installed aiohttp version on your system
- Compare the output version against 3.14.1; any version below 3.14.1 indicates a vulnerable installation
- Search application logs for unusual memory consumption spikes or out-of-memory errors, especially during HTTP request processing: grep -i 'memoryerror\|oom\|out of memory' /var/log/app/*.log
- After applying the patch, re-run the version check to confirm aiohttp is updated to 3.14.1 or later
FAQ
What is CVE-2026-54278?
This vulnerability affects aiohttp's request body decompression logic, allowing attackers to trigger memory exhaustion through specially crafted compressed payloads that decompress into single large chunks during cleanup operations, similar to zip bomb attacks.
Is CVE-2026-54278 being actively exploited?
No, this vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities catalog, and no public exploits are known at this time. However, the high CVSS score warrants prompt patching.
What versions of Python are affected by CVE-2026-54278?
Any system running aiohttp versions prior to 3.14.1 is affected. The vulnerability exists across all minor versions up to 3.14.0 regardless of the underlying Python version.
How do I check if my server is vulnerable to CVE-2026-54278?
Execute 'python3 -m pip show aiohttp | grep Version' to display the installed aiohttp version. If the version is below 3.14.1, your server is vulnerable.
Does Defensia detect CVE-2026-54278?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If aiohttp is installed on a monitored server, CVE-2026-54278 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-54278. Free for 1 server.
Get started free