---
schema_version: '1.0'
id: security-20260714-e1a21e
url: https://osv.dev/vulnerability/PYSEC-2026-2107
url_hash: e1a21ebcb7c111272a48716f2d611f0b30d3da7975ae9400cd31effc187f99da
canonical_url: https://osv.dev/vulnerability/PYSEC-2026-2107
source: osv:pypa
category: security/library
category_raw: cve/library
region: null
tags:
- cve
- CVE-2026-54273
- PYSEC-2026-2107
- severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- aiohttp
- PyPI
lang: en
published_at: '2026-06-22T18:16:45Z'
fetched_at: '2026-07-14T06:42:23Z'
updated_at: '2026-07-14T06:42:55Z'
status: published
content_hash: 8b988b546f101497252ea32def028ed10ee30d21eb2eaba568273279103e5749
license_note: full
summary: AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python.
  Prior to 3.14.1, no limit was present on the number of pipelined requests that could
  be queued. An attacker may be able to use pipelined requests to use excessive amounts
  of memory, potentially leadin
summary_source: rss
summary_en: AIOHTTP is an asynchronous HTTP client/server framework for asyncio and
  Python. Prior to 3.14.1, no limit was present on the number of pipelined requests
  that could be queued. An attacker may be able to use pipelined requests to use excessive
  amounts of memory, potentially leadin
entities: []
key_facts: []
related: []
related_auto: []
title: CVE-2026-54273 — aiohttp
---

# CVE-2026-54273 — aiohttp

## TL;DR
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on the number of pipelined requests that could be queued. An attacker may be able to use pipelined requests to use excessive amounts of memory, potentially leadin

## Key Points
- cve / CVE-2026-54273 / PYSEC-2026-2107 / severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H / aiohttp / PyPI

## Details
**Severity:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
**Advisory:** PYSEC-2026-2107 (CVE-2026-54273)

**Affected (your watchlist):**
- `PyPI:aiohttp` 3.13.3 → fixed in 3.14.1 [docker/docker-strands]

**Details:**
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on the number of pipelined requests that could be queued. An attacker may be able to use pipelined requests to use excessive amounts of memory, potentially leading to DoS. This vulnerability is fixed in 3.14.1.

**References:**
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-4fvr-rgm6-gqmc
- https://github.com/aio-libs/aiohttp/commit/dfdfa9d5aad5d21f91c79fb2ceeba0f8046cb6cf

_Data: OSV.dev (upstream: pypa) — https://osv.dev/vulnerability/PYSEC-2026-2107_

## Source
元記事: [CVE-2026-54273 — aiohttp](https://osv.dev/vulnerability/PYSEC-2026-2107) — published 2026-06-22T18:16:45Z
