Memory Consumption Vulnerability in AIOHTTP Framework by Aio-libs
CVE-2026-34516

6.6MEDIUM

Key Information:

Vendor

Aio-libs

Status
Vendor
CVE Published:
1 April 2026

What is CVE-2026-34516?

AIOHTTP, an asynchronous HTTP client/server framework for Python, is susceptible to a memory consumption issue that could facilitate a denial-of-service (DoS) attack. Prior to version 3.13.4, the framework permitted responses containing an excessive number of multipart headers, leading to unintended memory usage and potential performance degradation. This problem has been addressed in version 3.13.4, which now limits memory allocation and enhances overall stability. Users are encouraged to update immediately to mitigate the risks associated with this vulnerability.

Affected Version(s)

aiohttp < 3.13.4

References

CVSS V4

Score:
6.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.