GHSA-xcgm-r5h9-7989 on CTRL-OS 26.05
Aliases: GHSA-xcgm-r5h9-7989, CVE-2026-54274
Packages: python3Packages.aiohttp
Status: Plausible
Advisory Information
Summary
If an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual size limits on memory use.
Impact
If a web application has WebSocket endpoints, it may be possible for an attacker to execute a DoS attack through excessive memory use.
Patch: https://github.com/aio-libs/aiohttp/commit/14b6ee851fb16ec199acb950de0c82d476799e7d
Updates
2026-07-10 22:13 CEST
Metadata changes:
- Status for package
python3Packages.aiohttp: “Plausible”
(Amended on: 2026-07-10 22:14 CEST)
2026-07-10 20:35 CEST
Metadata changes:
- Status for package
python3Packages.aiohttp: “New”