Junglewise Threat Intelligence

CVE-2026-34513: PYSEC-2026-2095 - AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result

CVE-2026-34513 · Severity: medium · CVSS 4 · Published 2026-04-01

Technologies: aiohttp (PyPI). Vendors: PyPI.

Executive brief

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation. This issue has been patched in version 3.13.4.

Affected products

  • PyPI aiohttp

Related threats