aioHTTP < 3.10.11 Request Smuggling

medium Nessus Plugin ID 211645

Version 1.6

Aug 19, 2025, 4:04 PM

  • CVSS metrics ("Cvssv4 threat score" set to 6.3)
  • CVSS metrics ("Cvssv4 threat vector" set to "CVSS:4.0/E:U")
  • CVSS temporal metrics ("CVSSv2 temporal vector" set to "CVSS2#E:U/RL:OF/RC:C")
  • CVSS temporal metrics ("CVSSv3 temporal vector" set to "CVSS:3.0/E:U/RL:O/RC:C")

Plugin Feed: 202508191604

Version 1.5

Aug 18, 2025, 4:31 PM

  • CVSS metrics ("CVSSv2 score" set to 7.8)
  • CVSS metrics ("CVSSv2 vector" set to "CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N")
  • CVSS metrics ("CVSSv3 score" set to 7.5)
  • CVSS metrics ("CVSSv3 vector" set to "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N")
  • CVSS metrics ("Cvssv4 score" set to 6.3)
  • CVSS metrics ("Cvssv4 threat score" set to 6.3)
  • CVSS metrics ("Cvssv4 vector" set to "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N")
  • CVSSv2 severity (based on CVE-2024-52304, severity increased from "Low" to "High")
  • CVSSv2 severity (based on None, severity decreased from "High" to "Medium")
  • CVSSv3 severity (based on None, severity increased from "Low" to "High")

Plugin Feed: 202508181631

Version 1.4

Feb 4, 2025, 10:34 AM

  • Detection (improved regex)

Plugin Feed: 202502041034

Version 1.3

Nov 22, 2024, 6:54 PM

  • IAVM reference
  • STIG Severity (changed from "II" to "I")

Plugin Feed: 202411221854

Version 1.1

Nov 20, 2024, 8:07 PM

  • New

Plugin Feed: 202411202007

* Changelogs are generally available for changes made after Nov 1, 2022