CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-0190: Denial of Service in aimhubio/aim

7.5 CVSS

Description

In version 3.25.0 of aimhubio/aim, a denial of service vulnerability exists. By tracking a large number of `Text` objects and then querying them simultaneously through the web API, the Aim web server becomes unresponsive to other requests for an extended period while processing and returning these objects. This vulnerability can be exploited repeatedly, leading to a complete denial of service.

Classification

CVE ID: CVE-2025-0190

CVSS Base Severity: HIGH

CVSS Base Score: 7.5

CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem Types

CWE-1049 Excessive Data Query Operations in a Large Data Table

Affected Products

Vendor: aimhubio

Product: aimhubio/aim

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 16.35% (scored less or equal to compared to others)

EPSS Date: 2025-04-18 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-0190
https://huntr.com/bounties/38d151f1-abb4-443a-86b0-6c26f0c6cb70

Timeline