Vulnerability Description
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.10.11, the Python parser parses newlines in chunk extensions incorrectly which can lead to request smuggling vulnerabilities under certain conditions. If a pure Python version of aiohttp is installed (i.e. without the usual C extensions) or `AIOHTTP_NO_EXTENSIONS` is enabled, then an attacker may be able to execute a request smuggling attack to bypass certain firewalls or proxy protections. Version 3.10.11 fixes the issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aiohttp | Aiohttp | < 3.10.11 |
Related Weaknesses (CWE)
References
- https://github.com/aio-libs/aiohttp/commit/259edc369075de63e6f3a4eaade058c62af0dPatch
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-8495-4g3g-x7prVendor Advisory
- https://lists.debian.org/debian-lts-announce/2025/02/msg00002.html
FAQ
What is CVE-2024-52304?
CVE-2024-52304 is a vulnerability with a CVSS score of 7.5 (HIGH). aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.10.11, the Python parser parses newlines in chunk extensions incorrectly which can lead to request sm...
How severe is CVE-2024-52304?
CVE-2024-52304 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-52304?
Check the references section above for vendor advisories and patch information. Affected products include: Aiohttp Aiohttp.