CVE-2026-22815
published 2026-04-01CVE-2026-22815: AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.44%
36.0th percentile
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This issue has been patched in version 3.13.4.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| aio-libs | aiohttp | < 3.13.4 | 3.13.4 |
| aiohttp | aiohttp | < 3.13.4 | 3.13.4 |
| aiohttp | aiohttp | >= 0 < 3.13.4 | 3.13.4 |
| debian | python-aiohttp | — | — |
| ubuntu | python-aiohttp | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv6.9MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
AIOHTTP vulnerabilities
vendor_ubuntu·2026-07-22·CVSS 7.5
CVE-2026-34513 [HIGH] AIOHTTP vulnerabilities
Title: AIOHTTP vulnerabilities
Summary: Several security issues were fixed in AIOHTTP.
Sean Gilligan discovered that AIOHTTP did not properly limit memory
usage when processing HTTP headers and trailers. An attacker could
possibly use this issue to consume excessive system resources, resulting
in a denial of service. (CVE-2026-22815)
It was discovered that AIOHTTP did not properly limit the size of its
DNS cache. An attacker could possibly use this issue to consume
excessive system resources, resulting in a denial of service.
(CVE-2026-34513)
Mingi Jung discovered that AIOHTTP did not properly sanitize the
content_type parameter. An attacker could possibly use this issue to
inject malicious HTTP headers, resulting in HTTP response splitting.
(CVE-2026-34514)
It was discovered that AIO
Red Hat
aiohttp: AIOHTTP: Denial of Service via insufficient header/trailer handling
vendor_redhat·2026-04-01·CVSS 6.9
CVE-2026-22815 [MEDIUM] CWE-770 aiohttp: AIOHTTP: Denial of Service via insufficient header/trailer handling
aiohttp: AIOHTTP: Denial of Service via insufficient header/trailer handling
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This issue has been patched in version 3.13.4.
A flaw was found in AIOHTTP, an asynchronous HTTP client/server framework for Python. Insufficient restrictions in header and trailer handling could allow a remote attacker to cause uncapped memory usage. This can lead to a Denial of Service (DoS) condition, making the affected web server unavailable.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and dep
Debian
CVE-2026-22815: python-aiohttp - AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. ...
vendor_debian·2026·CVSS 6.9
CVE-2026-22815 [MEDIUM] CVE-2026-22815: python-aiohttp - AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. ...
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This issue has been patched in version 3.13.4.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
OSV
aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage
osv·2026-04-01
CVE-2026-22815 [MEDIUM] aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage
aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage
### Summary
Insufficient restrictions in header/trailer handling could cause uncapped memory usage.
### Impact
An application could cause memory exhaustion when receiving an attacker controlled request or response. A vulnerable web application could mitigate these risks with a typical reverse proxy configuration.
Patch: https://github.com/aio-libs/aiohttp/commit/0c2e9da51126238a421568eb7c5b53e5b5d17b36
GHSA
aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage
ghsa·2026-04-01
CVE-2026-22815 [MEDIUM] CWE-400 aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage
aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage
### Summary
Insufficient restrictions in header/trailer handling could cause uncapped memory usage.
### Impact
An application could cause memory exhaustion when receiving an attacker controlled request or response. A vulnerable web application could mitigate these risks with a typical reverse proxy configuration.
Patch: https://github.com/aio-libs/aiohttp/commit/0c2e9da51126238a421568eb7c5b53e5b5d17b36
OSV
CVE-2026-22815: AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python
osv·2026-04-01·CVSS 6.9
CVE-2026-22815 [MEDIUM] CVE-2026-22815: AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This issue has been patched in version 3.13.4.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-22815 aiohttp: AIOHTTP: Denial of Service via insufficient header/trailer handling
bugzilla·2026-04-01·CVSS 6.9
CVE-2026-22815 [MEDIUM] CVE-2026-22815 aiohttp: AIOHTTP: Denial of Service via insufficient header/trailer handling
CVE-2026-22815 aiohttp: AIOHTTP: Denial of Service via insufficient header/trailer handling
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This issue has been patched in version 3.13.4.
Wiz
CVE-2026-22815 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.9
CVE-2026-22815 [MEDIUM] CVE-2026-22815 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22815 :
Wolfi vulnerability analysis and mitigation
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This issue has been patched in version 3.13.4.
Source : NVD
## 6.9
Score
Published April 1, 2026
Severity MEDIUM
CNA Score 6.9
Affected Technologies
Wolfi
Chainguard
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 16.3
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
python-aiohttp
checkov
Sources
NVD
Chainguard Has Fix Added at: Apr 02, 2026
Debian 11, 12, 13, 14 Severity HIGH No Fix Added at: Apr 05, 202
2026-04-01
Published