Related Vulnerabilities: CVE-2022-33124  

** DISPUTED ** AIOHTTP 3.8.1 can report a "ValueError: Invalid IPv6 URL" outcome, which can lead to a Denial of Service (DoS). NOTE: multiple third parties dispute this issue because there is no example of a context in which denial of service would occur, and many common contexts have exception handing in the calling application.

Description

The MITRE CVE dictionary describes this issue as:

** DISPUTED ** AIOHTTP 3.8.1 can report a "ValueError: Invalid IPv6 URL" outcome, which can lead to a Denial of Service (DoS). NOTE: multiple third parties dispute this issue because there is no example of a context in which denial of service would occur, and many common contexts have exception handing in the calling application.

Additional Information

  • Bugzilla 2103107: CVE-2022-33124 python-aiohttp: invalid IPv6 URL which can lead to a Denial of Service with exception raised
  • CWE-20: Improper Input Validation
  • FAQ: Frequently asked questions about CVE-2022-33124