USN-8591-1: AIOHTTP vulnerabilities
Sean Gilligan discovered that AIOHTTP did not properly limit memory usage when processing HTTP headers and trailers. An attacker could possibly use this issue to consume excessive system resources, resulting in a denial of service. (CVE-2026-22815) It was discovered that AIOHTTP did not properly limit the size of its DNS cache. An attacker could possibly use this issue to consume excessive system resources, resulting in a denial of service. (CVE-2026-34513) Mingi Jung discovered that AIOHTTP did not properly sanitize the content_type parameter. An attacker could possibly use this issue to inject malicious HTTP headers, resulting in HTTP response splitting. (CVE-2026-34514) It was discovered that AIOHTTP did not properly limit memory usage when processing multipart headers. An attacker could possibly use this issue to consume excessive system resources, resulting in a denial of service. (CVE-2026-34516)
CSIRTS triage
- What
- AIOHTTP has multiple vulnerabilities that could lead to denial of service and HTTP response splitting.
- Who is affected
- Deployments of AIOHTTP that process HTTP headers and trailers.
- Urgency
- Remediation is urgent due to the potential for resource exhaustion and service disruption.
- Action
- Update to the latest version of AIOHTTP to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch AIOHTTP
Get an email when a new AIOHTTP advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8591-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-228150.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all scored CVEs.
- Low exploitation riskCVE-2026-345130.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all scored CVEs.
- Low exploitation riskCVE-2026-345140.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all scored CVEs.
- Low exploitation riskCVE-2026-345160.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-22815 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34513 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34514 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34516 | coverage & exploitation status | NVD · CVE.org |
More from Ubuntu Security Notices
- highUSN-8620-4: Linux kernel (Intel IoTG) vulnerabilities2026-07-31
- highUSN-8620-3: Linux kernel (Intel IoTG) vulnerabilities2026-07-31
- unknownUSN-8625-1: OpenSSL vulnerability2026-07-30
- unknownUSN-8624-1: Sinatra vulnerability2026-07-29
- unknownUSN-8623-1: Linux kernel (NVIDIA) vulnerabilities2026-07-29