Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:brew/vdirsyncer

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Vdirsyncer versions from 0.19.0 up to but not including 0.19.2_4 are affected by a vulnerability in a dependency, aiohttp, which uses llhttp 8.1.1. This version of llhttp is vulnerable to two request smuggling vulnerabilities. The issue is resolved by upgrading to llhttp 9 or later, which is included in aiohttp 3.8.6 and newer.

Join the discussion

### Summary Insufficient restrictions in header/trailer handling could cause uncapped memory usage. ### Impact An application could cause memory exhaustion when receiving an attacker controlled request or response. A vulnerable web application could mitigate these risks with a typical reverse proxy configuration. ----- Patch: https://github.com/aio-libs/aiohttp/commit/0c2e9da51126238a421568eb7c5b53e5b5d17b36

Join the discussion

### Summary Attacker-controlled input included into multipart/payload headers can be used to modify a request to inject additional headers or similar. ### Impact In the unlikely situation that an application is passing user-controlled strings into `MultipartWriter.append(headers=...)` or `Payload.headers`, then an attacker may be able to modify the request to inject headers or change the contents of the request. ### Workaround Sanitise such user input. ----- Patch: https://github.com/aio-libs/aiohttp/commit/bf88077ebb14f4c29924b8e8904cba20c55c28b8

Join the discussion

### Summary The client accepts and decompresses frames with the RSV1 bit set even when the `permessage-deflate` extension was not negotiated. ### Impact A client may unexpectedly decompress WebSocket frames when explicitly opted out. This could lead to additional CPU/memory consumption, but is unlikely to be a significant issue unless a zip bomb vulnerability or similar is also present. --- Patch: https://github.com/aio-libs/aiohttp/commit/47fb6ae354d4fa22048f4dbe7dbf82b625f0a2f6

Join the discussion

A vulnerability in AIOHTTP's CookieJar.load() function allows deserialization of untrusted data, potentially enabling arbitrary code execution. This flaw affects applications that load attacker-controlled files, which is not common in typical deployments. A patch is available to address this issue. Applications should sanitize input files before loading to mitigate risk if they handle untrusted data.

Join the discussion

An out-of-bounds heap read vulnerability exists in the C HTTP response parser of vdirsyncer when handling malformed chunked responses. This flaw can cause a denial of service (DoS) if an attacker-controlled server or an accidental malformed response triggers the error path. A patch is available to fix this issue. As a workaround, users can disable the C parser by setting the environment variable AIOHTTP_NO_EXTENSIONS=1 to use the unaffected Python parser.

Join the discussion

A vulnerability in aiohttp's Python parser incorrectly handles newlines in chunk extensions, which can lead to HTTP request smuggling attacks under certain conditions. This affects aiohttp when used in pure Python mode without C extensions or when the environment variable AIOHTTP_NO_EXTENSIONS is enabled. The vulnerability is addressed by an available patch. Red Hat has released updates for affected products including Ansible Automation Platform 2.5. Exploitation could allow attackers to bypass firewall or proxy protections.

Join the discussion

### Summary The Python parser parses newlines in chunk extensions incorrectly which can lead to request smuggling vulnerabilities under certain conditions. ### Impact If a pure Python version of aiohttp is installed (i.e. without the usual C extensions) or `AIOHTTP_NO_EXTENSIONS` is enabled, then an attacker may be able to execute a request smuggling attack to bypass certain firewalls or proxy protections. ----- Patch: https://github.com/aio-libs/aiohttp/commit/259edc369075de63e6f3a4eaade058c62af0df71

Join the discussion

### Summary When assert statements are bypassed, an infinite loop can occur, resulting in a DoS attack when processing a POST body. ### Impact If optimisations are enabled (`-O` or `PYTHONOPTIMIZE=1`), and the application includes a handler that uses the `Request.post()` method, then an attacker may be able to execute a DoS attack with a specially crafted message. ------ Patch: https://github.com/aio-libs/aiohttp/commit/bc1319ec3cbff9438a758951a30907b072561259

Join the discussion

### Summary The Python parser is vulnerable to a request smuggling vulnerability due to not parsing trailer sections of an HTTP request. ### Impact If a pure Python version of aiohttp is installed (i.e. without the usual C extensions) or AIOHTTP_NO_EXTENSIONS is enabled, then an attacker may be able to execute a request smuggling attack to bypass certain firewalls or proxy protections. ---- Patch: https://github.com/aio-libs/aiohttp/commit/e8d774f635dc6d1cd3174d0e38891da5de0e2b6a

Join the discussion

Showing 1 to 10 of 12 results

Filters:Package: pkg:brew/vdirsyncer
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses