HIGH 7.5 PyPI

Aim allows denial of service due to no timeouts for some tracking server endpoints

GHSA-6w7p-xrvp-p7xv · CVE-2024-8061 · PYSEC-2026-1083

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

In version 3.23.0 of aimhubio/aim, certain methods that request data from external servers do not have set timeouts, causing the server to wait indefinitely for a response. This can lead to a denial of service, as the tracking server does not respond to other requests while waiting. The issue arises in the client used by the aim tracking server to communicate with external resources, specifically in the _run_read_instructions method and similar calls without timeouts.

Ready to move

Start Securing

Free, no credit card | First findings in minutes