CVE-2026-34517

Aliases:GHSA-3wq7-rqq7-wx6jPYSEC-2026-2099UBUNTU-CVE-2026-34517DEBIAN-CVE-2026-34517CGA-2w3c-p7cp-vfr9CGA-386v-3phj-c9grCGA-39pp-j4wg-7687CGA-5qx6-vxjw-m7jvCGA-6724-vq96-9vpfCGA-87rx-vr9x-43rrCGA-c923-3gqw-8qprCGA-crhj-pw8h-vm2rCGA-frr2-22fq-5w77CGA-hmqc-fqqg-j57rCGA-j5f7-rmqj-xf2qCGA-j9wr-xg54-2pmwCGA-jgjx-7756-5m74CGA-2454-pvwv-4849CGA-3whq-w43m-684fCGA-3wrh-r8g6-cjm4CGA-3x3g-hff9-f9g7CGA-4fhq-wpwp-xw56CGA-4fj8-m95c-h8prCGA-4v7q-xp63-qcf9CGA-556c-4qp3-pmxhCGA-55fv-jrg2-2m64CGA-5hhw-5xxr-88p9CGA-5wm6-8cpp-g7c4CGA-6363-m4xr-7wppCGA-76mr-pffm-5wv7CGA-7j5v-x4w8-f5ghCGA-7m2g-46rp-9cwvCGA-84pq-g3j9-2ghxCGA-8639-4p3v-c8w9CGA-88j2-jq74-9qcqCGA-8jqq-rm46-xxw3CGA-8x92-whjf-j2vqCGA-92c6-6799-mvvfCGA-956g-37h6-p26wCGA-c2rm-jf2r-43gjCGA-cj4g-2xgg-v6hwCGA-fc7f-jg7c-mq5mCGA-gv3m-9m43-cg6xCGA-h4mx-jf2r-ghp8CGA-hm57-m3q2-w7phCGA-j3cw-v988-fwxxCGA-j8cg-p5fq-77gwCGA-jrcr-7w25-m52jCGA-pg45-wj57-4r8hCGA-pqx2-34p3-7g4fCGA-q887-6cfx-555mCGA-qm2j-q8x3-c63gCGA-qq45-hgvw-xm96CGA-qqwx-pfc9-rjm9CGA-qxgx-pf29-rmxqCGA-r5jf-gpm8-5cwhCGA-rr84-hv56-63q5CGA-rrjm-7pqw-gxwvCGA-rv7g-qf63-66jrCGA-v27v-pwmq-54j5CGA-v98g-wmpc-3h8wCGA-vx3j-gwrg-957mCGA-w5vq-f3mf-5vpqCGA-xg5m-j478-cvxr
Analyzed
Published: 01 Apr 2026, 20:14
Last modified:23 Jun 2026, 15:50

Vulnerability Summary

Overall Risk (default)
low
21/100
CVSS Score
5.3 MEDIUM
v3.1 (nvd)
EPSS Score
0.38% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

01 Apr 2026, 20:14
Published
Vulnerability first disclosed
23 Jun 2026, 15:50
Last Modified
Vulnerability information updated

Description

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, for some multipart form fields, aiohttp read the entire field into memory before checking client_max_size. This issue has been patched in version 3.13.4.

CVSS Metrics

  • v4.0LOWScore: 2.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U
  • v4.0LOWScore: 2.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

EPSS Trends

Current EPSS score: 0.38% Percentile: 32%

Techniques & Countermeasures

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • aio-libsaiohttp

    < 3.13.4

  • aiohttpaiohttp

    < 3.13.4

  • chainguardairflow-2

    < 2.11.2-r5

  • chainguardairflow-3

    < 3.2.1-r0 | < 3.1.8-r11

  • chainguardairflow-core-2

    < 2.11.2-r3

  • chainguardauthentik-2025.12

    < 2025.12.4-r3

  • chainguardauthentik-2026.2

    < 2026.2.1-r3

  • chainguardauthentik-fips-2025.12

    < 2025.12.4-r3

  • chainguardauthentik-fips-2026.2

    < 2026.2.1-r3

  • chainguardawx

    < 24.6.1-r33

  • chainguardcheckov

    < 3.2.517-r0

  • chainguarddask-kubernetes

    < 2026.3.0-r3

  • chainguarddatahub-ingestion

    < 1.6.0-r1

  • chainguarddatahub-ingestion-fips

    < 1.5.0.1-r1

  • chainguardkeep-api

    < 0.51.0-r2

  • chainguardkeep-api-fips

    < 0.51.0-r2

  • chainguardkserve-storage-controller

    < 0.17.0-r2

  • chainguardkubeflow-pipelines-visualization-server

    < 2.16.0-r4

  • chainguardlitellm

    < 1.82.3.0-r3

  • chainguardmetaflow-service

    < 2.5.0-r10

  • chainguardmetaflow-service-fips

    < 2.5.0-r2

  • chainguardopen-webui

    < 0.8.12-r3

  • chainguardpy3-cassandra-medusa

    < 0.27.1-r2

  • chainguardpy3.13-scanner-test-libraries-aiohttp

    < 0.0.1-r3

  • chainguardrequest-1276

    < 0.27.1-r2

  • chainguardtext-generation-inference

    < 3.3.7-r10

  • chainguardtritonserver-backend-vllm-cuda-12.9

    < 25.9.0_git20260318-r1

  • chainguardtritonserver-backend-vllm-cuda-13.0

    < 25.11-r3

  • wolfiairflow-3

    < 3.2.1-r0 | < 3.1.8-r11

  • wolficheckov

    < 3.2.517-r0

  • wolfidask-kubernetes

    < 2026.3.0-r3

  • wolfikserve-storage-controller

    < 0.17.0-r2

  • wolfikubeflow-pipelines-visualization-server

    < 2.16.0-r4

  • wolfiopen-webui

    < 0.8.12-r3

  • wolfipy3-cassandra-medusa

    < 0.27.1-r2

  • debianpython-aiohttp

    < 3.7.4-1+deb11u2 | all | all | < 3.13.5-1

  • ubuntupython-aiohttp

    all | all

  • PyPIaiohttp

    < 3.13.4

References (9)