Integer overflow in aiohttp - #VU153859
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to temporarily exhaust the connection pool.
The vulnerability exists due to an overflow in Max-Age processing when handling Max-Age values. A remote attacker can trigger an overflow that prevents a connection from closing to temporarily exhaust the connection pool.
Garbage collection eventually resolves the unclosed connections.