CVE-2026-54273Medium▾ Sunlitaiohttp: HTTP/1 Pipelined Requests Queue Without Limit
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.3%
Last analysed / modified upstream
No limit was present on the number of pipelined requests that could be queued.
An attacker may be able to use pipelined requests to use excessive amounts of memory, potentially leading to DoS.
Patch: https://github.com/aio-libs/aiohttp/commit/dfdfa9d5aad5d21f91c79fb2ceeba0f8046cb6cf
aiohttp < 3.14.1Upgrade to a patched release:
aiohttp 3.14.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54277Mediumaiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines
CVE-2026-54274Mediumaiohttp: Incomplete websocket frame payloads bypass memory limits
CVE-2025-69223High· 7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python
GHSA-pjjw-qhg8-p2p9Mediumaiohttp has vulnerable dependency that is vulnerable to request smuggling
CVE-2023-47627Medium· 5.3AIOHTTP has problems in HTTP parser (the python one, not llhttp)
CVE-2024-23334Medium· 5.9aiohttp is vulnerable to directory traversal