High severity7.5NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026
CVE-2024-8061
CVE-2024-8061
Description
In version 3.23.0 of aimhubio/aim, certain methods that request data from external servers do not have set timeouts, causing the server to wait indefinitely for a response. This can lead to a denial of service, as the tracking server does not respond to other requests while waiting. The issue arises in the client used by the aim tracking server to communicate with external resources, specifically in the _run_read_instructions method and similar calls without timeouts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
aimPyPI | <= 3.23.0 | — |
Affected products
3- aimhubio/aimhubio/aimv5Range: unspecified
Patches
Vulnerability mechanics
References
4- huntr.com/bounties/c85d005c-b354-4c51-a88f-adda2f09622bnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-6w7p-xrvp-p7xvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-8061ghsaADVISORY
- github.com/aimhubio/aim/blob/a6c6f2fee0f1abe37c1d66701b0329fb6af31a3d/aim/ext/transport/client.pyghsaWEB
News mentions
0No linked articles in our index yet.