HIGH 7.5 PyPI

Aim Uncontrolled Resource Consumption vulnerability

GHSA-35p3-6j45-prwm · CVE-2024-12778 · PYSEC-2026-1080

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service (DoS) attack. The issue arises when a large number of tracked metrics are retrieved simultaneously from the Aim web API, causing the web server to become unresponsive. The root cause is the lack of a limit on the number of metrics that can be requested per call, combined with the server's single-threaded nature, leading to excessive resource consumption and blocking of the server.

Ready to move

Start Securing

Free, no credit card | First findings in minutes