Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
## This update for python-aiohttp fixes the following issues * CVE-2026-22815: insufficient restrictions in header/trailer handling can cause uncapped memory usage and a denial of service (bsc#1261320). * CVE-2026-34513: unbounded DNS cache can cause a excessive memory usage and lead to a denial of service (bsc#1261321). * CVE-2026-34514: `content_type` parameter manipulation can lead to header injection (bsc#1261322). * CVE-2026-34516: response with excessive multipart headers can use more memory than intended and cause a denial of service (bsc#1261329). * CVE-2026-34517: large multipart form fields read into memory without size check can cause a denial of service (bsc#1261331). * CVE-2026-34518: retained `Cookie` and `Proxy-Authorization` headers when
* bsc#1261320
* bsc#1261321
* bsc#1261322
* bsc#1261329
* bsc#1261331
* bsc#1261332
* bsc#1261334
* bsc#1261335
* bsc#1261343
* bsc#1267471
* bsc#1267561
* bsc#1268398
* bsc#1268543
* bsc#1268544
* bsc#1268549
* bsc#1268556
* bsc#1268559
* bsc#1268560
* bsc#1268561
Cross-
* CVE-2026-22815
* CVE-2026-34513
* CVE-2026-34514
* CVE-2026-34516
* CVE-2026-34517
* CVE-2026-34518
* CVE-2026-34519
* CVE-2026-34520
* CVE-2026-34525
* CVE-2026-34993
* CVE-2026-47265
* CVE-2026-50269
* CVE-2026-54273
* CVE-2026-54274
* CVE-2026-54275
* CVE-2026-54277
* CVE-2026-54278
* CVE-2026-54279
* CVE-2026-54280
CVSS scores:
* CVE-2026-22815 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-22815 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Get the latest Linux and open source security news straight to your inbox.