QID 997007

Date Published: 2024-01-31

QID 997007: Python (Pip) Security Update for aiohttp (GHSA-8qpw-xqxj-h4r2)

Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to protect against injection of additional requests. Additionally, validation could trigger exceptions that were not handled consistently with processing of other malformed input.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Github security advisory GHSA-8qpw-xqxj-h4r2 for updates and patch information.
    Vendor References

    CVEs related to QID 997007

    Software Advisories
    Advisory ID Software Component Link
    GHSA-8qpw-xqxj-h4r2 aiohttp URL Logo github.com/advisories/GHSA-8qpw-xqxj-h4r2