[pkg-vuln] CVE-2026-34513 in aiohttp@3.13.3 #322

Closed
opened 2026-04-02 17:37:20 +00:00 by kert · 0 comments
Owner

Severity: LOW
Package: aiohttp @ 3.13.3
Fixed in: 3.13.4

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation. This issue has been patched in version 3.13.4.

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-34513

**Severity:** LOW **Package:** `aiohttp` @ `3.13.3` **Fixed in:** `3.13.4` AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation. This issue has been patched in version 3.13.4. **Reference:** https://nvd.nist.gov/vuln/detail/CVE-2026-34513
kert added this to the P21: Package Supply Chain — inventory, mirrors, drift, vuln scanning milestone 2026-04-02 17:37:20 +00:00
kert added the ciquality labels 2026-04-02 17:37:20 +00:00
kert closed this issue 2026-04-10 00:57:09 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: homelab/stack#322