{"id":"CVE-2026-54274","aliases":["GHSA-xcgm-r5h9-7989","PYSEC-2026-2108"],"url":"https://o3.security/vulnerability/CVE-2026-54274","summary":"AIOHTTP: Incomplete websocket frame payloads bypass memory limits","details":"### Summary\n\nIf an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual size limits on memory use.\n\n### Impact\n\nIf a web application has WebSocket endpoints, it may be possible for an attacker to execute a DoS attack through excessive memory use.\n\n-----\n\nPatch: https://github.com/aio-libs/aiohttp/commit/14b6ee851fb16ec199acb950de0c82d476799e7d","published":"2026-06-22T16:33:37.789Z","modified":"2026-08-12T03:51:10.381375642Z","cvss":null,"epss":{"score":0.00305,"percentile":0.22718,"asOf":"2026-09-02"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"aiohttp","fixedVersion":"3.14.1"}],"fix":{"url":"https://github.com/aio-libs/aiohttp/commit/14b6ee851fb16ec199acb950de0c82d476799e7d","label":"aio-libs/aiohttp@14b6ee8"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54274.json"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-xcgm-r5h9-7989"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54274"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/14b6ee851fb16ec199acb950de0c82d476799e7d"},{"type":"PACKAGE","url":"https://github.com/aio-libs/aiohttp"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:10.381375642Z"}}