Vulnerability record · CVE-2024-23334 · published 29 January 2024
CVE-2024-23334: aiohttp static route path traversal when follow_symlinks is enabled
Aiohttp · Aiohttp
aiohttp, an asynchronous HTTP client/server framework for Python, fails to validate that files read through static routes remain inside the configured root directory when the follow_symlinks option is set to True. This allows directory traversal and unauthorized reading of arbitrary files on the host, even without symlinks present. Version 3.9.2 fixes the issue.
Description
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option 'follow_symlinks' can be used to determine whether to follow symbolic links outside the static root directory. When 'follow_symlinks' is set to True, there is no validation to check if reading a file is within the root directory. This can lead to directory traversal vulnerabilities, resulting in unauthorized access to arbitrary files on the system, even when symlinks are not present. Disabling follow_symlinks and using a reverse proxy are encouraged mitigations. Version 3.9.2 fixes this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityCVSS 7.5 with network reachability, no authentication, high confidentiality impact, and very high EPSS despite not being in KEV.
What it is
aiohttp, an asynchronous HTTP client/server framework for Python, fails to validate that files read through static routes remain inside the configured root directory when the follow_symlinks option is set to True. This allows directory traversal and unauthorized reading of arbitrary files on the host, even without symlinks present. Version 3.9.2 fixes the issue.
Impact
An unauthenticated remote attacker can read arbitrary files accessible to the aiohttp process, potentially exposing configuration, credentials, source code, or other sensitive data. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network via HTTP requests to a static route on an aiohttp server configured with follow_symlinks=True. No authentication or user interaction is required per the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
Not listed in CISA KEV, but EPSS is 0.76875 (99.5th percentile) and the vendor advisory and an Exploit-DB entry are tagged as exploit-related, indicating public exploit material exists.
What to do
- Upgrade aiohttp to version 3.9.2 or later.
- Set follow_symlinks to False on static routes where possible.
- Place a reverse proxy in front of aiohttp to normalize and restrict request paths.
- Apply distribution updates for Fedora and Debian packages that bundle aiohttp.
- Restrict filesystem permissions for the aiohttp process to limit exposure of sensitive files.
Detection
- Monitor HTTP requests containing path traversal sequences such as ../ or encoded variants against static routes.
- Alert on access to files outside the configured static root directory by the aiohttp process.
- Audit aiohttp configurations for static routes with follow_symlinks=True.
- Use file integrity or access monitoring to detect reads of sensitive files by the web server user.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-23334 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-23334), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.