CVE-2024-52303 - CVE House
Back to Database
Status published High CVE-2024-52303

aiohttp memory leak when middleware is enabled when requesting a resource with a non-allowed method

Vulnerability Description

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions starting with 3.10.6 and prior to 3.10.11, a memory leak can occur when a request produces a MatchInfoError. This was caused by adding an entry to a cache on each request, due to the building of each MatchInfoError producing a unique cache entry. An attacker may be able to exhaust the memory resources of a server by sending a substantial number (100,000s to millions) of such requests. Those who use any middlewares with aiohttp.web should upgrade to version 3.10.11 to receive a patch.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-52303

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

aiohttp
Vulnerable Versions:
>= 3.10.6, < 3.10.11

Timeline

Official Publish: November 18th, 2024
Last Modified: November 19th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.