Insufficient restrictions in header/trailer handling could cause uncapped memory usage.
An application could cause memory exhaustion when receiving an attacker controlled request or response. A vulnerable web application could mitigate these risks with a typical reverse proxy configuration.
Patch: https://github.com/aio-libs/aiohttp/commit/0c2e9da51126238a421568eb7c5b53e5b5d17b36
{
"nvd_published_at": "2026-04-01T21:16:58Z",
"severity": "MODERATE",
"github_reviewed": true,
"cwe_ids": [
"CWE-400",
"CWE-770"
],
"github_reviewed_at": "2026-04-01T19:45:17Z"
}