aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disable `show_index` if unable to upgrade.

Project Subscriptions

Vendors Products
Aiohttp Subscribe
Aiohttp Subscribe
Fedoraproject Subscribe
Ansible Automation Platform Subscribe
Satellite Subscribe
Satellite Capsule Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-4041-1 python-aiohttp security update
EUVD EUVD EUVD-2024-1143 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disable `show_index` if unable to upgrade.
Github GHSA Github GHSA GHSA-7gpw-8wmc-pm8g aiohttp Cross-site Scripting vulnerability on index pages for static file handling
Ubuntu USN Ubuntu USN USN-7642-1 AIOHTTP vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 03 Nov 2025 21:30:00 +0000

Type Values Removed Values Added
References

Thu, 21 Aug 2025 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Fedoraproject
Fedoraproject fedora
CPEs cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
Vendors & Products Fedoraproject
Fedoraproject fedora

Thu, 13 Feb 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Aiohttp
Aiohttp aiohttp
CPEs cpe:2.3:a:aiohttp:aiohttp:*:*:*:*:*:*:*:*
Vendors & Products Aiohttp
Aiohttp aiohttp
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Feb 2025 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhui
CPEs cpe:/a:redhat:rhui:4::el8
Vendors & Products Redhat rhui

Wed, 21 Aug 2024 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat satellite
Redhat satellite Capsule
CPEs cpe:/a:redhat:satellite:6.15::el8
cpe:/a:redhat:satellite_capsule:6.15::el8
Vendors & Products Redhat satellite
Redhat satellite Capsule

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-03T20:37:02.696Z

Reserved: 2024-02-22T18:08:38.876Z

Link: CVE-2024-27306

cve-icon Vulnrichment

Updated: 2025-11-03T20:37:02.696Z

cve-icon NVD

Status : Modified

Published: 2024-04-18T15:15:29.050

Modified: 2025-11-03T21:16:08.463

Link: CVE-2024-27306

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-04-18T00:00:00Z

Links: CVE-2024-27306 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses