PT-2026-29605 · Aiohttp+1 · Aiohttp+1

·

CVE-2026-34516

·

Published

2026-03-10

·

Updated

2026-07-15

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AIOHTTP versions prior to 3.13.4
Description A response with an excessive number of multipart headers may be allowed to use more memory than intended, potentially leading to a denial-of-service condition. Multipart headers were not subject to the same size restrictions as normal headers, potentially allowing a larger amount of data to be loaded into memory than expected.
Recommendations Update to version 3.13.4 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09574
CLEANSTART-2026-AN27706
CLEANSTART-2026-AZ09261
CLEANSTART-2026-CQ05396
CLEANSTART-2026-FU07345
CLEANSTART-2026-KE11953
CLEANSTART-2026-MR94452
CLEANSTART-2026-NM83456
CLEANSTART-2026-QE89118
CLEANSTART-2026-SO50412
CLEANSTART-2026-WQ85001
CLEANSTART-2026-WU03167
CVE-2026-34516
ECHO-AC58-CDA1-4C8B
GHSA-M5QP-6W8W-W647
OESA-2026-2192
OESA-2026-2193
OESA-2026-2194
OPENSUSE-SU-2026:10545-1
OPENSUSE-SU-2026:21098-1
PYSEC-2026-2098
SUSE-SU-2026:22173-1
SUSE-SU-2026:3059-1

Affected Products

Aiohttp
Red Os