USN-8591-1

Published: 22 Jul 2026, 20:37
Last modified:23 Jul 2026, 20:52

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

22 Jul 2026, 20:37
Published
Vulnerability first disclosed
23 Jul 2026, 20:52
Last Modified
Vulnerability information updated

Description

python-aiohttp vulnerabilities Sean Gilligan discovered that AIOHTTP did not properly limit memory usage when processing HTTP headers and trailers. An attacker could possibly use this issue to consume excessive system resources, resulting in a denial of service. (CVE-2026-22815) It was discovered that AIOHTTP did not properly limit the size of its DNS cache. An attacker could possibly use this issue to consume excessive system resources, resulting in a denial of service. (CVE-2026-34513) Mingi Jung discovered that AIOHTTP did not properly sanitize the content_type parameter. An attacker could possibly use this issue to inject malicious HTTP headers, resulting in HTTP response splitting. (CVE-2026-34514) It was discovered that AIOHTTP did not properly limit memory usage when processing multipart headers. An attacker could possibly use this issue to consume excessive system resources, resulting in a denial of service. (CVE-2026-34516)

Affected Systems

  • ubuntupython-aiohttp

    < 0.20.2-1ubuntu0.1~esm1 | < 3.0.1-1ubuntu0.1~esm7 | < 3.6.2-1ubuntu1+esm6 | < 3.8.1-4ubuntu0.2+esm3 | < 3.9.1-1ubuntu0.1+esm3 | < 3.13.3-3ubuntu1+esm1

References (5)