THREAT OPS › Threat News › [NVD] CVE-2026-54280 (HIGH 7.5) — AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar limited resource, then an attacker may be
[NVD] CVE-2026-54280 (HIGH 7.5) — AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar limited resource, then an attacker may be
CVE-2026-54280 CVSS: 7.5 HIGH Published: 2026-06-22T18:16:46.670
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar limited resource, then an attacker may be able to cause resource starvation temporarily until ga
Indicators of compromise
- CVE-2026-54280cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-54280