PT-2026-66548 · Pypi · Aiohttp

CVE-2026-59881

·

Published

2026-07-30

·

Updated

2026-08-30

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions AIOHTTP versions prior to 3.14.2
Description The WebSocket client accepts and decompresses frames with the RSV1 bit set even when the permessage-deflate extension (a mechanism used to compress WebSocket messages to reduce bandwidth) was not negotiated. This behavior allows a malicious server to trigger unexpected CPU and memory consumption.
Recommendations Update to version 3.14.2.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-94397
CVE-2026-59881
ECHO-331A-ABDB-DB3B
GHSA-MQ44-7P77-Q5H7
OESA-2026-3277
OESA-2026-3278
OESA-2026-3279
OPENSUSE-SU-2026:11467-1
OPENSUSE-SU-2026:21687-1
PYSEC-2026-3547

Affected Products

Aiohttp