CVE-2026-34513
published 2026-04-01CVE-2026-34513: AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.44%
36.1th percentile
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation. This issue has been patched in version 3.13.4.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| aio-libs | aiohttp | < 3.13.4 | 3.13.4 |
| aiohttp | aiohttp | < 3.13.4 | 3.13.4 |
| aiohttp | aiohttp | >= 0 < 3.13.4 | 3.13.4 |
| debian | python-aiohttp | — | — |
| ubuntu | python-aiohttp | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.02.7LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv2.7LOW
vendor_ubuntu7.5HIGH
vendor_debian2.7LOW
vendor_redhat2.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector
ghsa·2026-04-01
CVE-2026-34513 [LOW] CWE-770 AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector
AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector
### Summary
An unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation.
### Impact
If an application makes requests to a very large number of hosts, this could cause the DNS cache to continue growing and slowly use excessive amounts of memory.
Patch: https://github.com/aio-libs/aiohttp/commit/c4d77c3533122be353b8afca8e8675e3b4cbda98
OSV
AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector
osv·2026-04-01
CVE-2026-34513 [LOW] AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector
AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector
### Summary
An unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation.
### Impact
If an application makes requests to a very large number of hosts, this could cause the DNS cache to continue growing and slowly use excessive amounts of memory.
Patch: https://github.com/aio-libs/aiohttp/commit/c4d77c3533122be353b8afca8e8675e3b4cbda98
OSV
CVE-2026-34513: AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python
osv·2026-04-01·CVSS 2.7
CVE-2026-34513 [LOW] CVE-2026-34513: AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation. This issue has been patched in version 3.13.4.
Ubuntu
AIOHTTP vulnerabilities
vendor_ubuntu·2026-07-22·CVSS 7.5
CVE-2026-34513 [HIGH] AIOHTTP vulnerabilities
Title: AIOHTTP vulnerabilities
Summary: Several security issues were fixed in AIOHTTP.
Sean Gilligan discovered that AIOHTTP did not properly limit memory
usage when processing HTTP headers and trailers. An attacker could
possibly use this issue to consume excessive system resources, resulting
in a denial of service. (CVE-2026-22815)
It was discovered that AIOHTTP did not properly limit the size of its
DNS cache. An attacker could possibly use this issue to consume
excessive system resources, resulting in a denial of service.
(CVE-2026-34513)
Mingi Jung discovered that AIOHTTP did not properly sanitize the
content_type parameter. An attacker could possibly use this issue to
inject malicious HTTP headers, resulting in HTTP response splitting.
(CVE-2026-34514)
It was discovered that AIO
Red Hat
aiohttp: AIOHTTP: Denial of Service due to unbounded DNS cache
vendor_redhat·2026-04-01·CVSS 2.7
CVE-2026-34513 [LOW] CWE-770 aiohttp: AIOHTTP: Denial of Service due to unbounded DNS cache
aiohttp: AIOHTTP: Denial of Service due to unbounded DNS cache
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation. This issue has been patched in version 3.13.4.
A flaw was found in AIOHTTP, an asynchronous HTTP client/server framework for asyncio and Python. This vulnerability allows a remote attacker to cause excessive memory usage by exploiting an unbounded Domain Name System (DNS) cache. This can lead to a Denial of Service (DoS) condition, making the service unavailable to legitimate users.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security crit
Debian
CVE-2026-34513: python-aiohttp - AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. ...
vendor_debian·2026·CVSS 2.7
CVE-2026-34513 [LOW] CVE-2026-34513: python-aiohttp - AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. ...
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation. This issue has been patched in version 3.13.4.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-34513 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.7
CVE-2026-34513 [LOW] CVE-2026-34513 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34513 :
Wolfi vulnerability analysis and mitigation
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation. This issue has been patched in version 3.13.4.
Source : NVD
## 2.7
Score
Published April 1, 2026
Severity LOW
CNA Score 2.7
Affected Technologies
Wolfi
Chainguard
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 16.4
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
metaflow-service-fips
python-aiohttp
Sources
NVD
Chainguard Has Fix Added at: Apr 02, 2026
Debian 11, 12, 13, 14 No Fix Added at: A
Bugzilla
CVE-2026-34513 aiohttp: AIOHTTP: Denial of Service due to unbounded DNS cache
bugzilla·2026-04-01·CVSS 2.7
CVE-2026-34513 [LOW] CVE-2026-34513 aiohttp: AIOHTTP: Denial of Service due to unbounded DNS cache
CVE-2026-34513 aiohttp: AIOHTTP: Denial of Service due to unbounded DNS cache
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation. This issue has been patched in version 3.13.4.
2026-04-01
Published