cbcvebase.
CVE-2024-30251
published 2024-05-02

CVE-2024-30251: aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attacker can send a specially crafted POST…

PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.09%
61.8th percentile
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attacker can send a specially crafted POST (multipart/form-data) request. When the aiohttp server processes it, the server will enter an infinite loop and be unable to process any further requests. An attacker can stop the application from serving requests after sending a single request. This issue has been addressed in version 3.9.4. Users are advised to upgrade. Users unable to upgrade may manually apply a patch to their systems. Please see the linked GHSA for instructions.

Affected

5 ranges
VendorProductVersion rangeFixed in
aio-libsaiohttp< 3.9.43.9.4
aiohttpaiohttp< 3.9.43.9.4
aiohttpaiohttp>= 0 < 3.9.43.9.4
debianpython-aiohttp< python-aiohttp 3.8.4-1+deb12u1 (bookworm)python-aiohttp 3.8.4-1+deb12u1 (bookworm)
msrcazl3_mozjs_102.15.1-1_on_azure_linux_3.0

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.