Allocation of Resources Without Limits or Throttling in aiohttp - CVE-2026-22815
Published: April 26, 2026
aiohttp
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in header/trailer handling when processing an attacker-controlled request or response. A remote attacker can send a specially crafted request or response to cause a denial of service.