Resource exhaustion in aiohttp - #VU133993
Published: June 9, 2026
aiohttp
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of compressed request bodies in request body cleanup when processing a compressed request body during cleanup. A remote attacker can send a specially crafted compressed payload to cause a denial of service.
This is a zip bomb edge case.