VDB
CVE-2026-54273
CVE-2026-54273
PUBLISHED
CVSS 6.6 MEDIUM
Reported by GitHub_M · Published June 22, 2026
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on the number of pipelined requests that could be queued. An attacker may be able to use pipelined requests to use excessive amounts of memory, potentially leading to DoS. This vulnerability is fixed in 3.14.1.
Risk Scores
CVSS 4.0
6.6
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| aio-libs | aiohttp | < 3.14.1 |
| chainguard | py3-vllm-cuda-13.0 | 0, 0, 0 |
| chainguard | authentik-fips-2026.2 | 0, 0, 0 |
| chainguard | open-webui | 0, 0, 0 |
| chainguard | airflow-3 | 0, 0, 0 |
| chainguard | py3-vllm-cuda-12.9 | 0, 0, 0 |
| chainguard | authentik-2026.2 | 0, 0, 0 |
| chainguard | authentik-2025.12 | 0, 0, 0 |
| chainguard | py3.13-scanner-test-libraries-aiohttp | 0, 0, 0 |
| chainguard | py3-vllm-cuda-12.4 | 0, 0, 0 |
| chainguard | mlflow | 0, 0, 0 |
| wolfi | airflow-3 | 0, 0, 0 |
| PyPI | aiohttp | 0 |
| chainguard | tritonserver-backend-vllm-cuda-12.9 | 0, 0, 0 |
| wolfi | mlflow | 0, 0, 0 |
| chainguard | text-generation-inference | 0, 0, 0 |
| chainguard | apache-beam-python-3.13-sdk | 0, 0, 0 |
| chainguard | dask-kubernetes-fips | 0, 0, 0 |
| chainguard | metaflow-service-fips | 0, 0, 0 |
| chainguard | authentik-fips-2025.12 | 0, 0, 0 |
…and 10 more
Timeline
- Jun 15, 2026 CVE Published
- Jun 23, 2026 Security Advisory
- Jun 26, 2026 CVE Updated
- Jul 4, 2026 EPSS Score
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Sep 4, 2026 EPSS Score
References
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-4fvr-rgm6-gqmc x_refsource_CONFIRM
- https://github.com/aio-libs/aiohttp/commit/dfdfa9d5aad5d21f91c79fb2ceeba0f8046cb6cf x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2026-54273 advisory
- https://github.com/advisories/GHSA-4fvr-rgm6-gqmc advisory