aio-libs aiohttp
cpe:2.3:a:aiohttp_project:aiohttp:*:*:*:*:*:*:*
- <= 3.13.2
A denial-of-service vulnerability has been identified in AIOHTTP versions through 3.13.2. This issue arises when multiple invalid cookies are read, leading to a excessive generation of warning-level logs. An attacker can exploit this vulnerability by sending a specially crafted Cookie header that triggers the logging storm. The problem occurs when the cookies attribute is accessed within an application.
Exploitation of this vulnerability causes a logging storm, generating excessive warning-level logs that can overwhelm logging systems and obscure important information.
Users can upgrade to AIOHTTP version 3.13.3 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.