[pkg-vuln] CVE-2026-54278 in aiohttp@3.13.5 #525

Closed
opened 2026-07-10 01:31:26 +00:00 by kert · 1 comment
Owner

Severity: MEDIUM
Package: aiohttp @ 3.13.5
Fixed in: 3.14.1

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1.

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-54278

**Severity:** MEDIUM **Package:** `aiohttp` @ `3.13.5` **Fixed in:** `3.14.1` AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1. **Reference:** https://nvd.nist.gov/vuln/detail/CVE-2026-54278
kert added this to the P21: Package Supply Chain — inventory, mirrors, drift, vuln scanning milestone 2026-07-10 01:31:26 +00:00
kert added the qualityci labels 2026-07-10 01:31:26 +00:00
Author
Owner

Not exploitable here. CVE-2026-54278 is a zip-bomb edge case when a server decompresses a request body during cleanup; server-side only, and no aiohttp server runs here. aiohttp enters this stack only as a transitive client dependency of the fsspec cloud-storage backends (s3fs / gcsfs / adlfs via aiobotocore — uv tree --invert --package aiohttp), talking to fixed, trusted storage endpoints. Nothing in the repo runs an aiohttp server or imports aiohttp directly.

Bumped anyway (defense in depth): aiohttp 3.13.5 → 3.14.1 in 65c31cf88f (uv.lock + pkg-manifest; pyproject floor raised for direct deps). Advisory link is in the issue body.

**Not exploitable here.** CVE-2026-54278 is a zip-bomb edge case when a server decompresses a request body during cleanup; server-side only, and no aiohttp server runs here. aiohttp enters this stack only as a transitive **client** dependency of the fsspec cloud-storage backends (s3fs / gcsfs / adlfs via aiobotocore — `uv tree --invert --package aiohttp`), talking to fixed, trusted storage endpoints. Nothing in the repo runs an aiohttp **server** or imports aiohttp directly. **Bumped anyway** (defense in depth): `aiohttp` 3.13.5 → 3.14.1 in https://git.fhirworx.io/homelab/stack/commit/65c31cf88fd8de552a006859159790de468403fb (uv.lock + pkg-manifest; pyproject floor raised for direct deps). Advisory link is in the issue body.
kert closed this issue 2026-07-10 17:18:58 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: homelab/stack#525