AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
Description
Published by the National Vulnerability Database
Jan 5, 2026
Published to the GitHub Advisory Database
Jan 5, 2026
Reviewed
Jan 5, 2026
Last updated
Jan 6, 2026
Summary
A zip bomb can be used to execute a DoS against the aiohttp server.
Impact
An attacker may be able to send a compressed request that when decompressed by aiohttp could exhaust the host's memory.
Patch: aio-libs/aiohttp@2b920c3
References