StackRadar

CVE-2024-52304

High

Advisory

Published 18 Nov 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
83
of 17,781 indexed, latest versions
Container images
84
deployed by those charts
Fix available
2 of 2
affected packages

aiohttp allows request smuggling due to incorrect parsing of chunk extensions

Carried by container images the latest versions of 83 of 17,781 indexed charts deploy, on 84 images.

Affected packageAffected versionsFixed inImages
python-aiohttpdeb3.8.4-13.8.4-1+deb12u11
aiohttppypi3.4.4, 3.5.4, 3.6.2, 3.7.1+15 more3.10.1184
OSV records
DEBIAN-CVE-2024-52304GHSA-8495-4g3g-x7pr
Also known as
PYSEC-2026-1103

Charts affected

83 by stars
ChartLatestAffected imagesRadar Score
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
aiohttp@3.8.1
3.10.11

Open the chart page →

17,779
buildkite-exporterminaVerified publisher0.1.41 of 1See more

buildkite-exporter mina 0.1.4

1 of the 1 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
codaprotocol/buildkite-exporter:0.2.137c68e67a401
aiohttp@3.7.3
3.10.11

Open the chart page →

2,599
mum-discord-botmum-discord-botVerified publisher0.3.71 of 1See more

mum-discord-bot mum-discord-bot 0.3.7

1 of the 1 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
aiohttp@3.9.1
3.10.11

Open the chart page →

13,686
mlflowncsaVerified publisher1.2.11 of 4See more

mlflow ncsa 1.2.1

1 of the 4 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
evk02/mlflow:2.2.1ef6ff257ef35
aiohttp@3.8.4
3.10.11

Open the chart page →

5,456
object-clonerobject-clonerVerified publisher2.0.01 of 1See more

object-cloner object-cloner 2.0.0

1 of the 1 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
ghcr.io/ideamixes/object-cloner:2.0.031030fd2f192
aiohttp@3.8.5
3.10.11

Open the chart page →

1,588
chatbot-ai-sampleopenshift0.1.61 of 4See more

chatbot-ai-sample openshift 0.1.6

1 of the 4 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
aiohttp@3.9.5
3.10.11

Open the chart page →

18,922
email-managerphntom0.1.221 of 2See more

email-manager phntom 0.1.22

1 of the 2 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
phntom/email-manager:0.1.22d8e2a9f2f085
aiohttp@3.8.4
3.10.11

Open the chart page →

2,565
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
apache/airflow:2.10.2-python3.9ce90bdc3d2af
aiohttp@3.10.5
3.10.11

Open the chart page →

21,211
radar-kafkaradar-baseVerified publisher0.4.11 of 2See more

radar-kafka radar-base 0.4.1

1 of the 2 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
ghcr.io/lsst-sqre/strimzi-registry-operator:0.6.07e25f7048aff
aiohttp@3.8.1
3.10.11

Open the chart page →

4,219
kube-web-viewrlex0.5.01 of 1See more

kube-web-view rlex 0.5.0

1 of the 1 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
hjacobs/kube-web-view:23.8.0431f1bf013d0
aiohttp@3.8.4
3.10.11

Open the chart page →

4,908
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
aiohttp@3.10.10
3.10.11

Open the chart page →

9,607
airflowsb-helm-charts0.3.01 of 1See more

airflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
apache/airflow:2.8.1e5560ad0b86e
aiohttp@3.9.1
3.10.11

Open the chart page →

10,209
ansible-semaphoresergiotocaliniVerified publisher1.2.01 of 1See more

ansible-semaphore sergiotocalini 1.2.0

1 of the 1 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.9.645b50bc11833f
aiohttp@3.8.5
3.10.11

Open the chart page →

3,337
verostakewise0.8.31 of 2See more

vero stakewise 0.8.3

1 of the 2 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
ghcr.io/serenita-org/vero:v0.8.3e5a7ec714acc
aiohttp@3.10.10
3.10.11

Open the chart page →

3,458
verbasubstratusVerified publisher0.4.01 of 1See more

verba substratus 0.4.0

1 of the 1 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
substratusai/verba:v0.4.0-baseURL261695be635eb
aiohttp@3.9.5
3.10.11

Open the chart page →

13,390
asrtest-opea1.0.01 of 1See more

asr test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
opea/asr:1.025dd26d9cd09
aiohttp@3.10.5
3.10.11

Open the chart page →

4,393
chatqnatest-opea1.0.05 of 11See more

chatqna test-opea 1.0.0

5 of the 11 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
opea/chatqna:1.038c51b791efa
aiohttp@3.10.5
3.10.11
opea/embedding-tei:1.05c9639de61c1
aiohttp@3.10.5
3.10.11
opea/llm-tgi:1.00c25aab3f106
aiohttp@3.10.5
3.10.11
opea/reranking-tei:1.0e48613afb191
aiohttp@3.10.5
3.10.11
opea/retriever-redis:1.0eb746b263705
aiohttp@3.10.5
3.10.11

Open the chart page →

39,090
codegentest-opea1.0.02 of 5See more

codegen test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
opea/codegen:1.058f91683892d
aiohttp@3.10.5
3.10.11
opea/llm-tgi:1.00c25aab3f106
aiohttp@3.10.5
3.10.11

Open the chart page →

28,814
codetranstest-opea1.0.02 of 5See more

codetrans test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
opea/codetrans:1.0e2436483b73d
aiohttp@3.10.5
3.10.11
opea/llm-tgi:1.00c25aab3f106
aiohttp@3.10.5
3.10.11

Open the chart page →

28,385
docsumtest-opea1.0.02 of 5See more

docsum test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
opea/docsum:1.03eaa91849512
aiohttp@3.10.5
3.10.11
opea/llm-docsum-tgi:1.002f9e8fa5d71
aiohttp@3.10.5
3.10.11

Open the chart page →

28,858
embedding-usvctest-opea1.0.01 of 1See more

embedding-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
opea/embedding-tei:1.05c9639de61c1
aiohttp@3.10.5
3.10.11

Open the chart page →

5,185
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
aiohttp@3.10.5
3.10.11

Open the chart page →

5,221
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
aiohttp@3.10.5
3.10.11

Open the chart page →

4,720
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
aiohttp@3.10.5
3.10.11

Open the chart page →

4,985
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
aiohttp@3.10.5
3.10.11

Open the chart page →

5,198
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
aiohttp@3.10.5
3.10.11

Open the chart page →

9,616
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
aiohttp@3.10.5
3.10.11

Open the chart page →

4,377
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
aiohttp@3.10.5
3.10.11

Open the chart page →

5,350
kasa-exporterth-chartsVerified publisher0.1.01 of 1See more

kasa-exporter th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
thelande/kasa_exporter:v0.2.3a1fdb8baa152
aiohttp@3.9.5
3.10.11

Open the chart page →

1,515
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
aiohttp@3.8.1
3.10.11

Open the chart page →

8,607
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
aiohttp@3.7.4
3.10.11

Open the chart page →

11,119
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
aiohttp@3.8.1
3.10.11

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-52304.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
aiohttp@3.8.1
3.10.11

Open the chart page →

1,636

Container images carrying it

84 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
opea/llm-tgi:1.00c25aab3f106
aiohttp@3.10.5
3.10.11
4
quay.io/devtron/ai-agent:0.0.16545dac92173
aiohttp@3.10.10
3.10.11
3
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
aiohttp@3.8.1
3.10.11
2
opea/embedding-tei:1.05c9639de61c1
aiohttp@3.10.5
3.10.11
2
opea/reranking-tei:1.0e48613afb191
aiohttp@3.10.5
3.10.11
2
opea/retriever-redis:1.0eb746b263705
aiohttp@3.10.5
3.10.11
2
vdiogov/glpi-conteiner:latest6945f84f0058
python-aiohttp@3.8.4-1
aiohttp@3.8.4
3.8.4-1+deb12u1
3.10.11
2
acockburn/appdaemon:4.0.83a93281d7e94
aiohttp@3.7.4
3.10.11
1
alerta/alerta-web:8.5.04786b9eaa606
aiohttp@3.8.0
3.10.11
1
apache/airflow:2.8.4-python3.964e58748b6b9
aiohttp@3.9.3
3.10.11
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
aiohttp@3.10.5
3.10.11
1
apache/airflow:2.8.1e5560ad0b86e
aiohttp@3.9.1
3.10.11
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
aiohttp@3.7.4
3.10.11
1
aristidetm/basic-notebook:3.6.5469dbc951224
aiohttp@3.9.5
3.10.11
1
aristidetm/k8s-hub:3.3.7ccb516cb8474
aiohttp@3.9.3
3.10.11
1
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
aiohttp@3.7.4
3.10.11
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
aiohttp@3.9.3
3.10.11
1
baserow/backend:1.31.1e0b3c8130b91
aiohttp@3.9.5
3.10.11
1
baserow/baserow:1.30.1df0c42eb67e8
aiohttp@3.9.5
3.10.11
1
codaprotocol/buildkite-exporter:0.2.137c68e67a401
aiohttp@3.7.3
3.10.11
1
deepflowce/deepflow-app:v6.2.6.5a1888d35e787
aiohttp@3.4.4
3.10.11
1
devopstales/trivy-operator:2.575136aa7a26e
aiohttp@3.8.3
3.10.11
1
evk02/mlflow:2.2.1ef6ff257ef35
aiohttp@3.8.4
3.10.11
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
aiohttp@3.8.3
3.10.11
1
flag5/clustersecret:0.0.94ad5748bfcc6
aiohttp@3.8.1
3.10.11
1
galaxy/cloudman-server:lateste5c265fe9fcd
aiohttp@3.8.1
3.10.11
1
guillh/web3-prometheus-exporter:0.3.04fb99dbc32b2
aiohttp@3.10.3
3.10.11
1
halkeye/slack-resurrect:v0.1.477b05e95fdb5
aiohttp@3.5.4
3.10.11
1
hayk96/alerta-web:9.0.486377705e9e3
aiohttp@3.10.5
3.10.11
1
hhyo/archery:v1.9.11aa41843419e
aiohttp@3.8.3
3.10.11
1
hjacobs/kube-web-view:23.8.0431f1bf013d0
aiohttp@3.8.4
3.10.11
1
hjacobs/kube-web-view:20.10.0b44a9cf81a2f
aiohttp@3.6.2
3.10.11
1
homeassistant/home-assistant:2023.10.3021e2afc6e57
aiohttp@3.8.5
3.10.11
1
homeassistant/home-assistant:2023.12.48d000332b09b
aiohttp@3.9.1
3.10.11
1
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
aiohttp@3.7.4
3.10.11
1
jupyterhub/k8s-hub:3.0.1-0.dev.git.6287.hbfb05cd65a0ceed1300a
aiohttp@3.8.5
3.10.11
1
langgenius/dify-api:0.6.11fca918260dd6
aiohttp@3.9.5
3.10.11
1
lsstsqre/kafkaaggregator:masterbe1b21060854
aiohttp@3.7.4
3.10.11
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
aiohttp@3.8.1
3.10.11
1
milesmcc/shynet:v0.13.1ba54f7797a6b
aiohttp@3.8.1
3.10.11
1
milesmcc/shynet:v0.12.0e821e31140f7
aiohttp@3.8.1
3.10.11
1
opea/asr:1.025dd26d9cd09
aiohttp@3.10.5
3.10.11
1
opea/chatqna:1.038c51b791efa
aiohttp@3.10.5
3.10.11
1
opea/codegen:1.058f91683892d
aiohttp@3.10.5
3.10.11
1
opea/codetrans:1.0e2436483b73d
aiohttp@3.10.5
3.10.11
1
opea/docsum:1.03eaa91849512
aiohttp@3.10.5
3.10.11
1
opea/guardrails-tgi:1.0262c6048aab8
aiohttp@3.10.5
3.10.11
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
aiohttp@3.10.5
3.10.11
1
opea/speecht5:1.0249afad3d268
aiohttp@3.10.5
3.10.11
1
opea/tts:1.0257ae94709e9
aiohttp@3.10.5
3.10.11
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.