CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

USN-8591-1: AIOHTTP vulnerabilities

unknownCVE-2026-22815CVE-2026-34513CVE-2026-34514CVE-2026-34516
Sean Gilligan discovered that AIOHTTP did not properly limit memory usage when processing HTTP headers and trailers. An attacker could possibly use this issue to consume excessive system resources, resulting in a denial of service. (CVE-2026-22815) It was discovered that AIOHTTP did not properly limit the size of its DNS cache. An attacker could possibly use this issue to consume excessive system resources, resulting in a denial of service. (CVE-2026-34513) Mingi Jung discovered that AIOHTTP did not properly sanitize the content_type parameter. An attacker could possibly use this issue to inject malicious HTTP headers, resulting in HTTP response splitting. (CVE-2026-34514) It was discovered that AIOHTTP did not properly limit memory usage when processing multipart headers. An attacker could possibly use this issue to consume excessive system resources, resulting in a denial of service. (CVE-2026-34516)

CSIRTS triage

What
AIOHTTP has multiple vulnerabilities that could lead to denial of service and HTTP response splitting.
Who is affected
Deployments of AIOHTTP that process HTTP headers and trailers.
Urgency
Remediation is urgent due to the potential for resource exhaustion and service disruption.
Action
Update to the latest version of AIOHTTP to mitigate these vulnerabilities.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch AIOHTTP

Get an email when a new AIOHTTP advisory drops — max one per day, one-click unsubscribe.

Details

Source
Ubuntu Security Notices (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-07-22
Exploitation
Not in CISA KEV at last sync

Original advisory: https://ubuntu.com/security/notices/USN-8591-1

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-22815coverage & exploitation statusNVD · CVE.org
CVE-2026-34513coverage & exploitation statusNVD · CVE.org
CVE-2026-34514coverage & exploitation statusNVD · CVE.org
CVE-2026-34516coverage & exploitation statusNVD · CVE.org

More from Ubuntu Security Notices