CVE-2024-52304
CVE-2024-52304 affects aiohttp, a Python HTTP client/server framework. This vulnerability involves incorrect parsing of newlines in chunk extensions by the Python parser, potentially leading to request smuggling. If aiohttp is installed without C extensions or with AIOHTTP_NO_EXTENSIONS
enabled, attackers could bypass firewalls or proxy protections. The fix is available in version 3.10.11. While the CVSS score is 0, SOCRadar's Vulnerability Risk Score (SVRS) is 30, indicating a low risk, but the "In The Wild" tag suggests potential active exploitation. This vulnerability is significant because successful exploitation can compromise backend systems via request manipulation.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.