AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client accepts and decompresses frames with the RSV1 bit set even when the permessage-deflate extension was not negotiated, allowing a malicious server to cause unexpected CPU and memory consumption. This issue is fixed in version 3.14.2.
CVSS
No CVSS.
References
Configurations
No configuration.
History
30 Jul 2026, 19:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-30 19:18
Updated : 2026-07-30 20:03
NVD link : CVE-2026-59881
Mitre link : CVE-2026-59881
CVE.ORG link : CVE-2026-59881
JSON object : View
Products Affected
No product.
CWE
CWE-20
Improper Input Validation
