CVE-2026-34513 affects AIOHTTP, an asynchronous HTTP client/server framework for Python, specifically versions prior to 3.13.4. The vulnerability stems from an unbounded DNS cache, which can lead to excessive memory usage and a potential denial-of-service (DoS) situation. This issue carries a low CVSS score of 2.7, indicating a low severity risk with low attack complexity and network exploitability. There is no evidence of active exploitation, public exploit code, or inclusion in the CISA KEV catalog, and community discussion is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.13.4CPE matchmatch criteria | cpe:2.3:a:aiohttp:aiohttp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.