[pkg-vuln] CVE-2026-34516 in aiohttp@3.13.3 #320

Closed
opened 2026-04-02 17:37:20 +00:00 by kert · 0 comments
Owner

Severity: MEDIUM
Package: aiohttp @ 3.13.3
Fixed in: 3.13.4

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, a response with an excessive number of multipart headers may be allowed to use more memory than intended, potentially allowing a DoS vulnerability. This issue has been patched in version 3.13.4.

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-34516

**Severity:** MEDIUM **Package:** `aiohttp` @ `3.13.3` **Fixed in:** `3.13.4` AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, a response with an excessive number of multipart headers may be allowed to use more memory than intended, potentially allowing a DoS vulnerability. This issue has been patched in version 3.13.4. **Reference:** https://nvd.nist.gov/vuln/detail/CVE-2026-34516
kert added this to the P21: Package Supply Chain — inventory, mirrors, drift, vuln scanning milestone 2026-04-02 17:37:20 +00:00
kert added the ciquality labels 2026-04-02 17:37:20 +00:00
kert closed this issue 2026-04-10 00:57:09 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: homelab/stack#320