Input validation error in aiohttp - CVE-2026-34516
Published: April 26, 2026
aiohttp
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in multipart header processing when parsing a response with an excessive number of multipart headers. A remote attacker can send a specially crafted response to cause a denial of service.
Other restrictions in place limit the impact of this vulnerability.