/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2023-47627

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2023-47627

CGA ID

CGA-r88q-7vqx-pch3

Severity

7.5

High

CVSS V3

Description

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parser is only used when AIOHTTP_NO_EXTENSIONS is enabled (or not using a prebuilt wheel). These bugs have been addressed in commit d5c12ba89 which has been included in release version 3.8.6. Users are advised to upgrade. There are no known workarounds for these issues.

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images