---
title: "CVE-2023-47641\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2023-47641?format=md
keywords: index, follow
---

# CVE-2023-47641

Publication date 14 November 2023

Last updated 26 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**3.4 · Low**

[Score breakdown](https://ubuntu.com/security/CVE-2023-47641?format=md#impact-score)

Toggle side navigation

## Description

aiohttp is an asynchronous HTTP client/server framework for asyncio and
Python. Affected versions of aiohttp have a security vulnerability
regarding the inconsistent interpretation of the http protocol. HTTP/1.1 is
a persistent protocol, if both Content-Length(CL) and Transfer-Encoding(TE)
header values are present it can lead to incorrect interpretation of two
entities that parse the HTTP and we can poison other sockets with this
incorrect interpretation. A possible Proof-of-Concept (POC) would be a
configuration with a reverse proxy(frontend) that accepts both CL and TE
headers and aiohttp as backend. As aiohttp parses anything with chunked, we
can pass a chunked123 as TE, the frontend entity will ignore this header
and will parse Content-Length. The impact of this vulnerability is that it
is possible to bypass any proxy rule, poisoning sockets to other users like
passing Authentication Headers, also if it is present an Open Redirect an
attacker could combine it to redirect random users to another website and
log the request. This vulnerability has been addressed in release 3.8.0 of
aiohttp. Users are advised to upgrade. There are no known workarounds for
this vulnerability.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| python-aiohttp | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Not affected |
| 24.04 LTS noble | Not affected |
| 23.10 mantic | Not affected |
| 23.04 lunar | Not affected |
| 22.04 LTS jammy | Not affected |
| 20.04 LTS focal | Needs evaluation |
| 18.04 LTS bionic | Needs evaluation |
| 16.04 LTS xenial | Needs evaluation |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

3.4 · Low

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | High |
  | Privileges required | None |
  | User interaction | Required |
  | Scope | Changed |
  | Confidentiality impact | Low |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 3.4 · Low |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-47641)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-47641)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2023-47641)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2023-47641)

### Other references

* <https://github.com/aio-libs/aiohttp/security/advisories/GHSA-xx9p-xxvh-7g8j>
* <https://github.com/aio-libs/aiohttp/commit/f016f0680e4ace6742b03a70cb0382ce86abe371 (v3.8.0b0)>
* <https://github.com/aio-libs/aiohttp/commit/f016f0680e4ace6742b03a70cb0382ce86abe371>
* <https://www.cve.org/CVERecord?id=CVE-2023-47641>
