CVE-2024-52303: aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method
(updated )
A memory leak can occur when a request produces a MatchInfoError
. This was caused by adding an entry to a cache on each request, due to the building of each MatchInfoError
producing a unique cache entry.
References
Detect and mitigate CVE-2024-52303 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →