CVE-2026-34513: AIOHTTP: Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector
Summary
An unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation.
Impact
If an application makes requests to a very large number of hosts, this could cause the DNS cache to continue growing and slowly use excessive amounts of memory.
-----
Patch: https://github.com/aio-libs/aiohttp/commit/c4d77c3533122be353b8afca8e8675e3b4cbda98
Other sources
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation. This issue has been patched in version 3.13.4.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/aiohttpto a version that resolves this vulnerability.Fixed in 3.13.4 - Upgrade
Upgrade
debian/python-aiohttpto a version that resolves this vulnerability.Fixed in 3.7.4-1+deb11u2Fixed in 3.14.1-4 - Upgrade
Upgrade
aiohttpto a version that resolves this vulnerability.Fixed in 3.13.4Patch c4d77c3533122be353b8afca8e8675e3b4cbda98