CVE-2024-27306

Aliases:GHSA-7gpw-8wmc-pm8gPYSEC-2026-1102DEBIAN-CVE-2024-27306CGA-2468-9f95-mr9hCGA-2rg8-fcwm-2j75CGA-45fm-5r7r-938hCGA-4cpm-jhwx-wf34CGA-5xcx-3r64-jq93CGA-6p5x-mvpc-c6g8CGA-6wjh-g2j4-26jjCGA-7phq-gcjh-m62wCGA-7qvj-m56w-m3fmCGA-9cfw-7hg6-6g2mCGA-9g92-xmgq-r5x5CGA-9j52-8h85-ggj9CGA-c2ph-9v2r-6692CGA-cr6r-mw5g-3838CGA-g4v6-f38r-jwj8CGA-hq96-59rf-46rvCGA-hxx9-q5rm-53vfCGA-m8mj-r63j-2552CGA-p6jg-962q-j4fjCGA-ph4r-4v3h-x92hCGA-3gjp-35gr-3v84CGA-92g8-r9mp-5wr3CGA-chpm-6qvh-5pv9CGA-hwvh-v762-hwg4CGA-p55m-84q5-f5pfCGA-q4gj-h366-3m97CGA-qhp7-5jqf-qf6gCGA-qvr6-7rqp-jgxwCGA-qxfq-gfx4-8g32CGA-r5xx-fq83-f7jcCGA-r9f3-gfrq-p3p2CGA-rf82-w8hr-57vwCGA-wfw5-2p8g-vf39CGA-wh52-gp5f-h9gvCGA-x2h3-9cqm-h7m3CGA-x6rh-hpmv-h436CGA-xv55-r4q4-hfc5
Modified
Published: 18 Apr 2024, 14:23
Last modified:03 Nov 2025, 20:37

Vulnerability Summary

Overall Risk (default)
medium
25/100
CVSS Score
6.1 MEDIUM
v3.1 (cve.org)
EPSS Score
0.67% LOW
1% probability -0.08%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

18 Apr 2024, 14:23
Published
Vulnerability first disclosed
03 Nov 2025, 20:37
Last Modified
Vulnerability information updated

Description

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disable `show_index` if unable to upgrade.

CVSS Metrics

  • v3.1MEDIUMScore: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS Trends

Current EPSS score: 0.67% Percentile: 50%

Techniques & Countermeasures

  • CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

  • CWE-80Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

    The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

Affected Systems

  • aio-libsaiohttp

    < 3.9.4

  • aiohttpaiohttp

    < 3.9.4

  • chainguardcheckov

    < 3.0.34-r1

  • chainguarddask-gateway

    < 2024.1.0-r4

  • chainguarddask-gateway-server

    < 2024.1.0-r4

  • chainguardkserve

    < 0.13.1-r3

  • chainguardkserve-agent

    < 0.13.1-r3

  • chainguardkserve-agent-compat

    < 0.13.1-r3

  • chainguardkserve-manager

    < 0.13.1-r3

  • chainguardkserve-manager-compat

    < 0.13.1-r3

  • chainguardkserve-qpext

    < 0.13.1-r3

  • chainguardkserve-qpext-compat

    < 0.13.1-r3

  • chainguardkserve-router

    < 0.13.1-r3

  • chainguardkserve-router-compat

    < 0.13.1-r3

  • chainguardkserve-storage-controller

    < 0.13.1-r3

  • chainguardnemo

    < 1.23.0-r12

  • chainguardpy3-cassandra-medusa

    < 0.20.1-r0

  • chainguardpy3-cassandra-medusa-compat

    < 0.20.1-r0

  • chainguardpy3.13-scanner-test-libraries-aiohttp

    < 0.0.1-r3

  • chainguardrequest-1276

    < 0.20.1-r0

  • chainguardrequest-1276-compat

    < 0.20.1-r0

  • wolficheckov

    < 3.0.34-r1

  • wolfidask-gateway

    < 2024.1.0-r4

  • wolfidask-gateway-server

    < 2024.1.0-r4

  • wolfikserve

    < 0.13.1-r3

  • wolfikserve-agent

    < 0.13.1-r3

  • wolfikserve-agent-compat

    < 0.13.1-r3

  • wolfikserve-manager

    < 0.13.1-r3

  • wolfikserve-manager-compat

    < 0.13.1-r3

  • wolfikserve-qpext

    < 0.13.1-r3

  • wolfikserve-qpext-compat

    < 0.13.1-r3

  • wolfikserve-router

    < 0.13.1-r3

  • wolfikserve-router-compat

    < 0.13.1-r3

  • wolfikserve-storage-controller

    < 0.13.1-r3

  • wolfipy3-cassandra-medusa

    < 0.20.1-r0

  • wolfipy3-cassandra-medusa-compat

    < 0.20.1-r0

  • debianpython-aiohttp

    < 3.7.4-1+deb11u1 | all | < 3.9.5-1 | < 3.9.5-1

  • fedoraprojectfedora

    38 | 39 | 40

  • PyPIaiohttp

    < 3.9.4

References (17)