Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p998-jp59-783m

Опубликовано: 01 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.6

Описание

AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows

Summary

On Windows the static resource handler may expose information about a NTLMv2 remote path.

Impact

If an application is running on Windows, and using aiohttp's static resource handler (not recommended in production), then it may be possible for an attacker to extract the hash from an NTLMv2 path and then extract the user's credentials from there.


Patch: https://github.com/aio-libs/aiohttp/commit/0ae2aa076c84573df83fc1fdc39eec0f5862fe3d

Пакеты

Наименование

aiohttp

pip
Затронутые версииВерсия исправления

<= 3.13.3

3.13.4

EPSS

Процентиль: 36%
0.00433
Низкий

6.6 Medium

CVSS4

Дефекты

CWE-36
CWE-918

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the static resource handler may expose information about a NTLMv2 remote path. This issue has been patched in version 3.13.4.

CVSS3: 5.3
redhat
4 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the static resource handler may expose information about a NTLMv2 remote path. This issue has been patched in version 3.13.4.

CVSS3: 7.5
nvd
4 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the static resource handler may expose information about a NTLMv2 remote path. This issue has been patched in version 3.13.4.

CVSS3: 7.5
debian
4 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

CVSS3: 7.5
fstec
5 месяцев назад

Уязвимость HTTP-клиента aiohttp, связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 36%
0.00433
Низкий

6.6 Medium

CVSS4

Дефекты

CWE-36
CWE-918