StackRadar

CVE-2024-30251

High

Advisory

Published 2 May 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.011
64th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
53
of 17,781 indexed, latest versions
Container images
54
deployed by those charts
Fix available
2 of 2
affected packages

aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests

Carried by container images the latest versions of 53 of 17,781 indexed charts deploy, on 54 images.

Affected packageAffected versionsFixed inImages
aiohttppypi3.4.4, 3.5.4, 3.6.2, 3.7.1+10 more3.9.454
python-aiohttpdeb3.8.4-13.8.4-1+deb12u11
OSV records
DEBIAN-CVE-2024-30251GHSA-5m98-qgg9-wh84
Also known as
PYSEC-2026-1098

Charts affected

53 by stars
ChartLatestAffected imagesRadar Score
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2024-30251.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
aiohttp@3.7.4
3.9.4

Open the chart page →

11,119
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-30251.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
aiohttp@3.8.1
3.9.4

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-30251.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
aiohttp@3.8.1
3.9.4

Open the chart page →

1,636

Container images carrying it

54 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/tauffer-consulting/domino-rest:latest8bf880fe8c73
aiohttp@3.8.3
3.9.4
1
quay.io/evl.ms/argocd-exporter:0.0.136ea8f34aa6b
aiohttp@3.7.4.post0
3.9.4
1
quay.io/jupyterhub/k8s-hub:3.2.12528c6e57587
aiohttp@3.9.1
3.9.4
1
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
aiohttp@3.8.1
3.9.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.