AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual size limits on memory use. This vulnerability is fixed in 3.14.1.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XAiohttp
APPAiohttp< 3.14.1
Related vulnerabilities
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allo...
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions starting with 3.10...
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attack...
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it po...
AIOHTTP to asynchroniczny framework klienta/serwera HTTP dla asyncio i Python. Przed wersją 3.14.1 brak był li...