CVE-2026-34520 affects AIOHTTP, an asynchronous HTTP framework, specifically versions prior to 3.13.4, where its default C parser improperly handled null bytes and control characters within HTTP response headers. This vulnerability carries a critical CVSS score of 9.1, indicating it is easily exploitable over a network without authentication or user interaction, potentially leading to high impacts on system integrity and availability. Despite being on a "Hot List," there is currently no evidence of active exploitation, nor are public exploit codes available on platforms like Metasploit or ExploitDB. Community discussion and media coverage remain very low, with only a single mention identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.13.4CPE matchmatch criteria | cpe:2.3:a:aiohttp:aiohttp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.