Allocation of Resources Without Limits or Throttling in aiohttp - #VU153862
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to exhaust file descriptors and cause resource exhaustion.
The vulnerability exists due to allocation of file descriptors without limits in Request.post() when processing multipart requests. A remote attacker can send specially crafted multipart requests to exhaust file descriptors and cause resource exhaustion.