HIGH7.5
PYSEC-2026-1081
Aim denial of service vulnerability
Details
A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to cause an infinite loop by configuring the remote tracking server to point at itself. This results in the server endlessly connecting to itself, rendering it unable to respond to other connections.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/aim
Introduced in:
0No fixed version published yet for aim (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-6227[ADVISORY]
- https://github.com/aimhubio/aim[PACKAGE]
- https://github.com/aimhubio/aim/blob/2e7b8aff8dcba9ddd5043dfec88cf2319ba8a87c/aim/sdk/repo.py#L195[WEB]
- https://huntr.com/bounties/abcea7c6-bb3b-45e9-aa15-9eb6b224451a[WEB]
- https://pypi.org/project/aim[PACKAGE]
- https://github.com/advisories/GHSA-36h2-g4c8-9xcm[ADVISORY]