THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-54280 (HIGH 7.5) — AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar limited resource, then an attacker may be

[NVD] CVE-2026-54280 (HIGH 7.5) — AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar limited resource, then an attacker may be

lownvdPublished 2026-06-22

CVE-2026-54280 CVSS: 7.5 HIGH Published: 2026-06-22T18:16:46.670

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar limited resource, then an attacker may be able to cause resource starvation temporarily until ga

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-54280