Input validation error in aiohttp - #VU133994
Published: June 9, 2026
aiohttp
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the C HTTP parser when processing fragmented HTTP request lines. A remote attacker can send specially crafted oversized fragmented lines to cause a denial of service.
Only deployments using the optimized C parser are affected.