Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-w2fm-2cpv-w7v5 | aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage |
Mon, 06 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aiohttp
Aiohttp aiohttp |
|
| CPEs | cpe:2.3:a:aiohttp:aiohttp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aiohttp
Aiohttp aiohttp |
Sat, 04 Apr 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
ssvc
|
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aio-libs
Aio-libs aiohttp |
|
| Vendors & Products |
Aio-libs
Aio-libs aiohttp |
Thu, 02 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This issue has been patched in version 3.13.4. | |
| Title | AIOHTTP: Uncapped memory usage possible through aiohttp allowing unlimited trailer headers | |
| Weaknesses | CWE-400 CWE-770 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-04T03:10:24.396Z
Reserved: 2026-01-09T22:50:10.288Z
Link: CVE-2026-22815
Updated: 2026-04-04T03:10:17.025Z
Status : Analyzed
Published: 2026-04-01T21:16:58.513
Modified: 2026-04-06T16:48:48.530
Link: CVE-2026-22815
OpenCVE Enrichment
Updated: 2026-04-07T08:07:30Z
Github GHSA