← Vulnerability feed

Vulnerability record · CVE-2024-23334 · published 29 January 2024

CVE-2024-23334: aiohttp static route path traversal when follow_symlinks is enabled

Aiohttp · Aiohttp

aiohttp, an asynchronous HTTP client/server framework for Python, fails to validate that files read through static routes remain inside the configured root directory when the follow_symlinks option is set to True. This allows directory traversal and unauthorized reading of arbitrary files on the host, even without symlinks present. Version 3.9.2 fixes the issue.

7.5 CVSS 3.1 High EPSS 77% · top 0.5% CWE-22 · Path traversal
7.5CVSS 3.1 base score
77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
12References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option 'follow_symlinks' can be used to determine whether to follow symbolic links outside the static root directory. When 'follow_symlinks' is set to True, there is no validation to check if reading a file is within the root directory. This can lead to directory traversal vulnerabilities, resulting in unauthorized access to arbitrary files on the system, even when symlinks are not present. Disabling follow_symlinks and using a reverse proxy are encouraged mitigations. Version 3.9.2 fixes this issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCVSS 7.5 with network reachability, no authentication, high confidentiality impact, and very high EPSS despite not being in KEV.

What it is

aiohttp, an asynchronous HTTP client/server framework for Python, fails to validate that files read through static routes remain inside the configured root directory when the follow_symlinks option is set to True. This allows directory traversal and unauthorized reading of arbitrary files on the host, even without symlinks present. Version 3.9.2 fixes the issue.

Impact

An unauthenticated remote attacker can read arbitrary files accessible to the aiohttp process, potentially exposing configuration, credentials, source code, or other sensitive data. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reachable over the network via HTTP requests to a static route on an aiohttp server configured with follow_symlinks=True. No authentication or user interaction is required per the CVSS vector AV:N/AC:L/PR:N/UI:N.

Exploitation

Not listed in CISA KEV, but EPSS is 0.76875 (99.5th percentile) and the vendor advisory and an Exploit-DB entry are tagged as exploit-related, indicating public exploit material exists.

What to do

  • Upgrade aiohttp to version 3.9.2 or later.
  • Set follow_symlinks to False on static routes where possible.
  • Place a reverse proxy in front of aiohttp to normalize and restrict request paths.
  • Apply distribution updates for Fedora and Debian packages that bundle aiohttp.
  • Restrict filesystem permissions for the aiohttp process to limit exposure of sensitive files.

Detection

  • Monitor HTTP requests containing path traversal sequences such as ../ or encoded variants against static routes.
  • Alert on access to files outside the configured static root directory by the aiohttp process.
  • Audit aiohttp configurations for static routes with follow_symlinks=True.
  • Use file integrity or access monitoring to detect reads of sensitive files by the web server user.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-23334 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2024-4577PHP-CGI on Windows argument injection leads to remote code executionPHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windo…KEVEPSS 100%analysed9.8CVE-2021-44026Roundcube Webmail SQL injection via search parametersRoundcube Webmail before 1.3.17 and 1.4.x before 1.4.12 is prone to SQL injection through the search or search_params input. The flaw is remotely rea…KEVEPSS 70%analysed9.8CVE-2021-42013Apache HTTP Server path traversal and RCE via incomplete fixThe fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient, leaving a path traversal flaw that lets attackers map URLs to files outside…KEVEPSS 100%analysed9.8CVE-2021-41773Apache HTTP Server 2.4.49 path traversal and RCEA path normalization flaw introduced in Apache HTTP Server 2.4.49 lets attackers map URLs to files outside directories configured by Alias-like direc…KEVEPSS 100%analysed9.8CVE-2021-1870Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions, affecting macOS Big Sur, Catalina, Mojave, iOS and iPadOS, plus WebKitGTK a…KEVEPSS 7.7%analysed9.8CVE-2021-1871Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions. It affects macOS Big Sur, Catalina, Mojave, iOS and iPadOS, and a remote at…KEVEPSS 7.0%analysed9.8CVE-2020-16846SaltStack Salt API shell injection via crafted web requestsSaltStack Salt through 3002 is vulnerable to OS command injection when the SSH client is enabled and crafted web requests are sent to the Salt API. T…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2024-23334), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.