[pkg-vuln] CVE-2026-54278 in aiohttp@3.13.5 #525
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Severity: MEDIUM
Package:
aiohttp@3.13.5Fixed in:
3.14.1AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1.
Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-54278
Not exploitable here. CVE-2026-54278 is a zip-bomb edge case when a server decompresses a request body during cleanup; server-side only, and no aiohttp server runs here. aiohttp enters this stack only as a transitive client dependency of the fsspec cloud-storage backends (s3fs / gcsfs / adlfs via aiobotocore —
uv tree --invert --package aiohttp), talking to fixed, trusted storage endpoints. Nothing in the repo runs an aiohttp server or imports aiohttp directly.Bumped anyway (defense in depth):
aiohttp3.13.5 → 3.14.1 in65c31cf88f(uv.lock + pkg-manifest; pyproject floor raised for direct deps). Advisory link is in the issue body.