CVE-2026-54274 | aio-libs aiohttp up to 3.14.0 WebSocket Frame allocation of resources (GHSA-xcgm-r5h9-7989 / EUVD-2026-38311)
A vulnerability was found in aio-libs aiohttp up to 3.14.0. It has been classified as problematic. The affected element is an unknown function of the component WebSocket Frame Handler. Performing a manipulation results in allocation of resources.
This vulnerability is identified as CVE-2026-54274. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.