CVE-2024-12778

A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service (DoS) attack. The issue arises when a large number of tracked metrics are retrieved simultaneously from the Aim web API, causing the web server to become unresponsive. The root cause is the lack of a limit on the number of metrics that can be requested per call, combined with the server's single-threaded nature, leading to excessive resource consumption and blocking of the server.
References
Link Resource
https://huntr.com/bounties/892a9eee-0251-4e57-94a4-dad2e7f32715 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:aimstack:aim:3.25.0:*:*:*:*:python:*:*

History

18 Jul 2025, 19:56

Type Values Removed Values Added
CPE cpe:2.3:a:aimstack:aim:3.25.0:*:*:*:*:python:*:*
First Time Aimstack aim
Aimstack
Summary
  • (es) Una vulnerabilidad en aimhubio/aim versión 3.25.0 permite un ataque de denegación de servicio (DoS). El problema surge cuando se recupera simultáneamente un gran número de métricas rastreadas desde la API web de Aim, lo que provoca que el servidor web deje de responder. La causa principal es la falta de un límite en el número de métricas que se pueden solicitar por llamada, junto con la naturaleza monohilo del servidor, lo que provoca un consumo excesivo de recursos y su bloqueo.
References () https://huntr.com/bounties/892a9eee-0251-4e57-94a4-dad2e7f32715 - () https://huntr.com/bounties/892a9eee-0251-4e57-94a4-dad2e7f32715 - Exploit, Third Party Advisory

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-07-18 19:56


NVD link : CVE-2024-12778

Mitre link : CVE-2024-12778

CVE.ORG link : CVE-2024-12778


JSON object : View

Products Affected

aimstack

  • aim
CWE
CWE-400

Uncontrolled Resource Consumption