VDB
GCVE-110-MAGEIA-2024-235
GCVE-110-MAGEIA-2024-235
Advisory Published
aiohttp is an asynchronous HTTP client/server framework for asyncio and
Python. A XSS vulnerability exists on index pages for static file
handling. This vulnerability is fixed in 3.9.4. We have always
recommended using a reverse proxy server (e.g. nginx) for serving static
files. Users following the recommendation are unaffected. Other users
can disable `show_index` if unable to upgrade.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | python-aiohttp | 0 (affected), 3.8.3-3.1.mga9 (unaffected), 0 (affected), 3.8.3-3.1.mga9 (unaffected) | — |
| Mageia | nvidia-current | 0 (affected), 550.135-1.mga9.nonfree (unaffected) | — |
Aliases
References
Browse GCVE Records
74,366 records in the GCVE database · Updated July 23, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.