J. Nick Koston
15 exploits
Active since Jan 2024
CPython 3.12.0-3.12.8, 3.13.0-3.13.1, 3.14.0a1-3.14.0a2 - Resource Consumption in asyncio
CVSS 7.5
CPython 3.12.0-3.12.8, 3.13.0-3.13.1, 3.14.0a1-3.14.0a2 - Resource Consumption in asyncio
CVSS 7.5
aiohttp - Directory Traversal
CVSS 5.9
aiohttp 3.10.0-3.10.2 - Path Traversal via Compressed File Symbolic Links
CVSS 4.8
AIOHTTP: Duplicate Host header accepted
CVSS 5.3
CPython 3.12.0-3.12.8, 3.13.0-3.13.1, 3.14.0a1-3.14.0a2 - Resource Consumption in asyncio
CVSS 7.5
aiohttp < 3.9.4 - Cross-Site Scripting in Static File Index Pages
CVSS 6.1
aiohttp <3.10.11 - Memory Corruption
CVSS 7.5
aiohttp <3.10.11 - Request Smuggling
CVSS 7.5
aiodns < 4.9.0 - Use-After-Free via Channel Object Garbage Collection
aiohttp < 3.13.3 - Denial of Service via Zip Bomb Decompression
CVSS 7.5
aiohttp < 3.13.3 - Path Traversal in Static File Path Normalization
CVSS 5.3
aiohttp < 3.13.3 - Denial of Service via POST Body Processing
CVSS 7.5
aiohttp < 3.13.3 - Denial of Service via Chunked Message Handling
CVSS 5.3
ESPHome 2025.9.0-2025.12.6 - Unauthenticated Denial of Service via API Protobuf Decoder Integer Overflow
CVSS 7.5