Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-22815

Опубликовано: 01 апр. 2026
Источник: debian

Описание

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This issue has been patched in version 3.13.4.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-aiohttpunfixedpackage

Примечания

  • https://github.com/aio-libs/aiohttp/security/advisories/GHSA-w2fm-2cpv-w7v5

  • Fixed by: https://github.com/aio-libs/aiohttp/commit/0c2e9da51126238a421568eb7c5b53e5b5d17b36 (v3.13.4)

Связанные уязвимости

ubuntu
1 день назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This issue has been patched in version 3.13.4.

CVSS3: 5.3
redhat
3 дня назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This issue has been patched in version 3.13.4.

nvd
3 дня назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This issue has been patched in version 3.13.4.

github
3 дня назад

aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage