aio-libs aiohttp
cpe:2.3:a:aiohttp_project:aiohttp:*:*:*:*:*:*:*
- <= 3.13.3
A denial-of-service vulnerability has been identified in AIOHTTP, an asynchronous HTTP client/server framework for Python. Prior to version 3.13.4, AIOHTTP's handling of certain multipart form fields allowed the entire field to be read into memory before enforcing the maximum client size limit. This behavior could be exploited to cause significant temporary memory usage, potentially leading to application performance issues or crashes.
Exploitation of this vulnerability can cause excessive memory consumption, leading to application slowdowns or crashes.
Users can upgrade to AIOHTTP version 3.13.4 or later to address this vulnerability. AIOHTTP version 3.13.4 is available on the Python Package Index (PyPI).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.