Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu python-aiohttp Important DoS Issues Fix 2026-8591-1

ubuntu
Calendar Grey July 22, 2026
Scroller Ubuntu
Significant security fixes in python-aiohttp for Ubuntu impacts multiple LTS releases. Recommended updates provided immediately.
Ubuntu issued an advisory on July 22, 2026, detailing vulnerabilities in python-aiohttp that could lead to denial of service and HTTP response splitting across multiple Ubuntu rele...

Summary

Several security issues were fixed in AIOHTTP.

Software Description:

- python-aiohttp: Asynchronous HTTP client/server Python framework

Details:

Sean Gilligan discovered that AIOHTTP did not properly limit memory

usage when processing HTTP headers and trailers. An attacker could

possibly use this issue to consume excessive system resources, resulting

in a denial of service. (CVE-2026-22815)

It was discovered that AIOHTTP did not properly limit the size of its

DNS cache. An attacker could possibly use this issue to consume

excessive system resources, resulting in a denial of service.

(CVE-2026-34513)

Mingi Jung discovered that AIOHTTP did not properly sanitize the

content_type parameter. An attacker could possibly use this issue to

inject malicious HTTP headers, resulting in HTTP response splitting.

(CVE-2026-34514)

It was discovered that AIOHTTP did not properly limit memory usage when

processing multipart headers. An attacker could possibly use this issue

to consume excessiv...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
  python3-aiohttp                 3.13.3-3ubuntu1+esm1
                                  Available with Ubuntu Pro

Ubuntu 24.04 LTS
  python3-aiohttp                 3.9.1-1ubuntu0.1+esm3
                                  Available with Ubuntu Pro

Ubuntu 22.04 LTS
  python3-aiohttp                 3.8.1-4ubuntu0.2+esm3
                                  Available with Ubuntu Pro

Ubuntu 20.04 LTS
  python3-aiohttp                 3.6.2-1ubuntu1+esm6
                                  Available with Ubuntu Pro

Ubuntu 18.04 LTS
  python3-aiohttp                 3.0.1-1ubuntu0.1~esm7
                                  Available with Ubuntu Pro

Ubuntu 16.04 LTS
  python3-aiohttp                 0.20.2-1ubuntu0.1~esm1
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8591-1

CVE-2026-22815, CVE-2026-34513, CVE-2026-34514, CVE-2026-34516

Severity
important
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8591-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.