Allocation of Resources Without Limits or Throttling in aiohttp - #VU153863
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service through resource exhaustion.
The vulnerability exists due to allocation of resources without limits or throttling in aiohttp when processing attacker-controlled requests. A remote attacker can send specially crafted requests to cause a denial of service through excessive or unbounded memory use or excessive CPU consumption.