Junglewise Threat Intelligence

CVE-2022-33124: aiohttp Denial of Service via invalid IPv6 URL (Withdrawn)

CVE-2022-33124 · Severity: medium · CVSS 5.5 · Published 2022-06-24

Technologies: aiohttp (PyPI). Vendors: PyPI.

Executive brief

A reported vulnerability in the aiohttp library, a popular tool for building web services in Python, was claimed to cause service crashes when processing certain web addresses. However, this report has been officially withdrawn because the software maintainers and independent experts found no evidence that the issue is valid. Organizations using this library do not need to take action as the threat was determined to be unsubstantiated.

Technical details

This advisory originally claimed that aiohttp v3.8.1 was susceptible to a Denial of Service (DoS) via the processing of invalid IPv6 URLs. The attack vector was described as local with required user interaction, potentially leading to high availability impact. However, the advisory was formally withdrawn on June 28, 2022, after the aiohttp maintainers and third parties disputed the validity of the findings. No patch was issued because the vulnerability could not be verified.

Affected products

  • aio-libs aiohttp <= 3.8.1

Timeline

  • 2022-06-23: disclosed: NVD publication date
  • 2022-06-24: advisory: GitHub Advisory published
  • 2022-06-28: other: Advisory officially withdrawn by GitHub and maintainers

References

Related threats