CVE-2026-54278
ADVISORY - githubSummary
Summary
During cleanup it is possible for a compressed request body to be decompressed into memory in one chunk.
Impact
An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case).
Workaround
Disable compression if unable to upgrade.
Patch: https://github.com/aio-libs/aiohttp/commit/4f7480e474cccc6a8cc2c92ad3f17a31dedf8232
Common Weakness Enumeration (CWE)
Improper Handling of Highly Compressed Data (Data Amplification)
GitHub
-
CVSS SCORE
6.6mediumDebian
-
CVSS SCORE
N/AlowUbuntu
3.9
CVSS SCORE
7.5mediumPypA
PYSEC-2026-2111
3.9
CVSS SCORE
7.5highChainguard
CGA-f7w5-386x-qjpj
-
minimos
MINI-7vhv-pg4x-45p6
-
minimos
MINI-8846-9f6q-64pj
-
minimos
MINI-92cc-2964-g2qc
-
minimos
MINI-cq23-hw7j-q5f4
-
minimos
MINI-fhrq-wx9v-pwpf
-
minimos
MINI-g5h2-qjvw-xrh9
-
minimos
MINI-h83g-32jq-mcjx
-
minimos
MINI-hrcx-gcjj-r4mm
-
minimos
MINI-jj2v-397q-h82h
-
minimos
MINI-r989-c52h-62vf
-
minimos
MINI-rc7w-6m26-285q
-
minimos
MINI-wp5h-8hwp-62m8
-
minimos
MINI-xgh9-m742-85rh
-