CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-22815

unknowncovered by 1 sourcefirst seen 2026-07-22
Sean Gilligan discovered that AIOHTTP did not properly limit memory usage when processing HTTP headers and trailers. An attacker could possibly use this issue to consume excessive system resources, resulting in a denial of service. (CVE-2026-22815) It was discovered that AIOHTTP did not properly limit the size of its DNS cache. An attacker could possibly use this issue to consume excessive system resources, resulting in a denial of service. (CVE-2026-34513) Mingi Jung discovered that AIOHTTP did not properly sanitize the content_type parameter. An attacker could possibly use this issue to inject malicious HTTP headers, resulting in HTTP response splitting. (CVE-2026-34514) It was discovered that AIOHTTP did not properly limit memory usage when processing multipart headers. An attacker could possibly use this issue to consume excessive system resources, resulting in a denial of service. (CVE-2026-34516)

CSIRTS triage

What
AIOHTTP has multiple vulnerabilities that could lead to denial of service and HTTP response splitting.
Who is affected
Deployments of AIOHTTP that process HTTP headers and trailers.
Urgency
Remediation is urgent due to the potential for resource exhaustion and service disruption.
Action
Update to the latest version of AIOHTTP to mitigate these vulnerabilities.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-22815

Get an email if CVE-2026-22815 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-22815

CVE.org record

Embed the live status

CVE-2026-22815 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-22815 status](https://www.csirts.com/badge/CVE-2026-22815)](https://www.csirts.com/cve/CVE-2026-22815)