CVE-2026-54278 | aio-libs aiohttp up to 3.14.0 Request Body data amplification (GHSA-g3cq-j2xw-wf74)
A vulnerability, which was classified as problematic, has been found in aio-libs aiohttp up to 3.14.0. Impacted is an unknown function of the component Request Body Handler. This manipulation causes highly compressed data.
This vulnerability is handled as CVE-2026-54278. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.