Junglewise Threat Intelligence

CVE-2026-34516: PYSEC-2026-2098 - AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, a response with an excessive number

CVE-2026-34516 · Severity: medium · CVSS 4 · Published 2026-04-01

Technologies: aiohttp (PyPI). Vendors: PyPI.

Executive brief

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, a response with an excessive number of multipart headers may be allowed to use more memory than intended, potentially allowing a DoS vulnerability. This issue has been patched in version 3.13.4.

Affected products

  • PyPI aiohttp

Related threats