In version 3.25.0 of aimhubio/aim, the tracking server is vulnerable to a denial of service attack. The server overrides the maximum size for websocket messages, allowing very large images to be tracked. This causes the server to become unresponsive to other requests while processing the large image, leading to a denial of service condition.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-6822 In version 3.25.0 of aimhubio/aim, the tracking server is vulnerable to a denial of service attack. The server overrides the maximum size for websocket messages, allowing very large images to be tracked. This causes the server to become unresponsive to other requests while processing the large image, leading to a denial of service condition.
Github GHSA Github GHSA GHSA-j5qj-rg5j-j7c2 Aim Uncontrolled Resource Consumption vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 15 Oct 2025 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Wed, 15 Oct 2025 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770

Fri, 28 Mar 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Aimstack
Aimstack aim
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:aimstack:aim:3.25.0:*:*:*:*:*:*:*
Vendors & Products Aimstack
Aimstack aim
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Thu, 20 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Mar 2025 10:15:00 +0000

Type Values Removed Values Added
Description In version 3.25.0 of aimhubio/aim, the tracking server is vulnerable to a denial of service attack. The server overrides the maximum size for websocket messages, allowing very large images to be tracked. This causes the server to become unresponsive to other requests while processing the large image, leading to a denial of service condition.
Title Denial of Service in aimhubio/aim
Weaknesses CWE-400
References
Metrics cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2025-10-15T12:50:04.149Z

Reserved: 2025-01-03T01:24:52.404Z

Link: CVE-2025-0189

cve-icon Vulnrichment

Updated: 2025-03-20T17:50:26.195Z

cve-icon NVD

Status : Modified

Published: 2025-03-20T10:15:51.660

Modified: 2025-10-15T13:16:00.253

Link: CVE-2025-0189

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.