CVE-2024-30251 Affecting python-aiohttp package, versions <3.9.5-1


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.05% (17th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN13-PYTHONAIOHTTP-6807506
  • published3 May 2024
  • disclosed2 May 2024

Introduced: 2 May 2024

CVE-2024-30251  (opens in a new tab)
First added by Snyk

How to fix?

Upgrade Debian:13 python-aiohttp to version 3.9.5-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream python-aiohttp package and not the python-aiohttp package as distributed by Debian. See How to fix? for Debian:13 relevant fixed versions and status.

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attacker can send a specially crafted POST (multipart/form-data) request. When the aiohttp server processes it, the server will enter an infinite loop and be unable to process any further requests. An attacker can stop the application from serving requests after sending a single request. This issue has been addressed in version 3.9.4. Users are advised to upgrade. Users unable to upgrade may manually apply a patch to their systems. Please see the linked GHSA for instructions.

CVSS Scores

version 3.1