diff --git a/meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-34517.patch b/meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-34517.patch
new file mode 100644
index 0000000000..577df52b0a
--- /dev/null
+++ b/meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-34517.patch
@@ -0,0 +1,65 @@
+From 70f4c611ec466b6a33f1bce57d5776fac964919f Mon Sep 17 00:00:00 2001
+From: "patchback[bot]" <45432694+patchback[bot]@users.noreply.github.com>
+Date: Tue, 10 Mar 2026 22:14:02 +0000
+Subject: [PATCH] [PR #12216/9cc4b917 backport][3.13] Check multipart max_size
+ during iteration (#12229)
+
+**This is a backport of PR #12216 as merged into master
+(9cc4b917c54833a22f65edae7963d16a6eeb1f54).**
+
+---------
+
+CVE: CVE-2026-34517
+Upstream-Status: Backport [https://github.com/aio-libs/aiohttp/commit/cbb774f38330563422ca0c413a71021d7b944145]
+
+Backport Changes:
+- Replaced BodyPartReader.decode_iter() with aiohttp 3.9.5's
+  synchronous decode() API. Form-data does not support content
+  compression, so this preserves upstream's single-decode behavior
+  after bounded chunk reads.
+
+Co-authored-by: Sam Bull <git@sambull.org>
+(cherry picked from commit cbb774f38330563422ca0c413a71021d7b944145)
+Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
+---
+ aiohttp/web_request.py | 19 +++++++++++++------
+ 1 file changed, 13 insertions(+), 6 deletions(-)
+
+diff --git a/aiohttp/web_request.py b/aiohttp/web_request.py
+index 2ec09565c..f9de59573 100644
+--- a/aiohttp/web_request.py
++++ b/aiohttp/web_request.py
+@@ -760,17 +760,24 @@ class BaseRequest(MutableMapping[str, Any], HeadersMixin):
+                         out.add(field.name, ff)
+                     else:
+                         # deal with ordinary data
+-                        value = await field.read(decode=True)
++                        raw_data = bytearray()
++                        while chunk := await field.read_chunk():
++                            size += len(chunk)
++                            if 0 < max_size < size:
++                                raise HTTPRequestEntityTooLarge(
++                                    max_size=max_size, actual_size=size
++                                )
++                            raw_data.extend(chunk)
++
++                        # aiohttp 3.9.5 has synchronous BodyPartReader.decode()
++                        # and form-data does not support content compression.
++                        value = field.decode(raw_data)
++
+                         if field_ct is None or field_ct.startswith("text/"):
+                             charset = field.get_charset(default="utf-8")
+                             out.add(field.name, value.decode(charset))
+                         else:
+                             out.add(field.name, value)
+-                        size += len(value)
+-                        if 0 < max_size < size:
+-                            raise HTTPRequestEntityTooLarge(
+-                                max_size=max_size, actual_size=size
+-                            )
+                 else:
+                     raise ValueError(
+                         "To decode nested multipart you need " "to use custom reader",
+-- 
+2.35.6
+
diff --git a/meta-python/recipes-devtools/python/python3-aiohttp_3.9.5.bb b/meta-python/recipes-devtools/python/python3-aiohttp_3.9.5.bb
index d7c7a5014a..fecf871d9f 100644
--- a/meta-python/recipes-devtools/python/python3-aiohttp_3.9.5.bb
+++ b/meta-python/recipes-devtools/python/python3-aiohttp_3.9.5.bb
@@ -23,6 +23,7 @@ SRC_URI += "file://CVE-2024-52304.patch \
            file://CVE-2026-34518.patch \
            file://CVE-2026-34519.patch \
            file://CVE-2026-34516.patch \
+           file://CVE-2026-34517.patch \
            "
 
 CVE_STATUS[CVE-2026-34515] = "not-applicable-platform: Vulnerability only affects applications running on Windows"
