PT-2026-29605 · Aiohttp+3 · Aiohttp+3

·

CVE-2026-34516

·

Publicado

2026-03-10

·

Atualizado

2026-08-21

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions AIOHTTP versões anteriores a 3.13.4
Description Uma resposta com um número excessivo de cabeçalhos multipart pode permitir o uso de mais memória do que o pretendido, potencialmente levando a uma condição de negação de serviço. Os cabeçalhos multipart não estavam sujeitos às mesmas restrições de tamanho que os cabeçalhos normais, permitindo potencialmente que uma quantidade maior de dados fosse carregada na memória do que o esperado.
Recommendations Atualize para a versão 3.13.4 ou posterior.

Exploit

Correção

DoS

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-81767
BDU:2026-09574
CLEANSTART-2026-AN24336
CLEANSTART-2026-AN27706
CLEANSTART-2026-AZ09261
CLEANSTART-2026-CQ05396
CLEANSTART-2026-EM82280
CLEANSTART-2026-FU07345
CLEANSTART-2026-HP19968
CLEANSTART-2026-IR98353
CLEANSTART-2026-KE11953
CLEANSTART-2026-MR94452
CLEANSTART-2026-NL78203
CLEANSTART-2026-NM83456
CLEANSTART-2026-QE89118
CLEANSTART-2026-SO50412
CLEANSTART-2026-WQ85001
CLEANSTART-2026-WU03167
CVE-2026-34516
ECHO-AC58-CDA1-4C8B
GHSA-M5QP-6W8W-W647
OESA-2026-2192
OESA-2026-2193
OESA-2026-2194
OPENSUSE-SU-2026:10545-1
OPENSUSE-SU-2026:21098-1
PYSEC-2026-2098
SUSE-SU-2026:22173-1
SUSE-SU-2026:3059-1
SUSE-SU-2026:3207-1
USN-8591-1

Produtos afetados

Aiohttp
Linuxmint
Red Os
Ubuntu