Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-54280

Gravedad CVSS v4.0:
BAJA
Tipo:
CWE-404 Apagado o liberación incorrecto de recursos
Fecha de publicación:
22/06/2026
Última modificación:
26/06/2026

Descripción

*** Pendiente de traducción *** AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar limited resource, then an attacker may be able to cause resource starvation temporarily until garbage collection or similar closes the file. This vulnerability is fixed in 3.14.1.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:aiohttp:aiohttp:*:*:*:*:*:*:*:* 3.14.1 (excluyendo)