---
schema_version: '1.0'
id: security-20260714-cf3c24
url: https://osv.dev/vulnerability/PYSEC-2026-2108
url_hash: cf3c24fe464676ff72c31cacab1f8c5d8ea35fbc99c87d79b4fb4be066f79add
canonical_url: https://osv.dev/vulnerability/PYSEC-2026-2108
source: osv:pypa
category: security/library
category_raw: cve/library
region: null
tags:
- cve
- CVE-2026-54274
- PYSEC-2026-2108
- severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- aiohttp
- PyPI
lang: en
published_at: '2026-06-22T18:16:45Z'
fetched_at: '2026-07-14T06:42:23Z'
updated_at: '2026-07-14T06:42:55Z'
status: published
content_hash: e9ebf2bde915e05f3da6c68548404ee312e51ba032be77880d8baf48aefbdd49
license_note: full
summary: AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python.
  Prior to 3.14.1, if an attacker sends large incomplete websocket frame payloads,
  it may be possible to bypass the usual size limits on memory use. This vulnerability
  is fixed in 3.14.1.
summary_source: rss
summary_en: AIOHTTP is an asynchronous HTTP client/server framework for asyncio and
  Python. Prior to 3.14.1, if an attacker sends large incomplete websocket frame payloads,
  it may be possible to bypass the usual size limits on memory use. This vulnerability
  is fixed in 3.14.1.
entities: []
key_facts: []
related: []
related_auto: []
title: CVE-2026-54274 — aiohttp
---

# CVE-2026-54274 — aiohttp

## TL;DR
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual size limits on memory use. This vulnerability is fixed in 3.14.1.

## Key Points
- cve / CVE-2026-54274 / PYSEC-2026-2108 / severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H / aiohttp / PyPI

## Details
**Severity:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
**Advisory:** PYSEC-2026-2108 (CVE-2026-54274)

**Affected (your watchlist):**
- `PyPI:aiohttp` 3.13.3 → fixed in 3.14.1 [docker/docker-strands]

**Details:**
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual size limits on memory use. This vulnerability is fixed in 3.14.1.

**References:**
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-xcgm-r5h9-7989
- https://github.com/aio-libs/aiohttp/commit/14b6ee851fb16ec199acb950de0c82d476799e7d

_Data: OSV.dev (upstream: pypa) — https://osv.dev/vulnerability/PYSEC-2026-2108_

## Source
元記事: [CVE-2026-54274 — aiohttp](https://osv.dev/vulnerability/PYSEC-2026-2108) — published 2026-06-22T18:16:45Z
