PT-2026-95665 · Pypi · Autobahn

CVE-2026-77528

·

Published

2026-09-18

·

Updated

2026-10-01

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Autobahn Python versions prior to 26.7.1
Description WebSocket endpoints that accept permessage-deflate and rely on maxMessagePayloadSize enforce the limit against the compressed frame length before inflation but fail to recheck the decompressed message size before delivery. A remote unauthenticated client can send a valid compressed frame that remains below the configured wire-size limit but expands beyond the application message limit upon decompression. This leads to the allocation, joining, and validation of oversized data passed to application callbacks, which can result in resource-exhaustion pressure.
Recommendations Update to version 26.7.1.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77528
GHSA-HXP9-W8X3-P566
OPENSUSE-SU-2026:11852-1
PYSEC-2026-4027
PYSEC-2026-4031

Affected Products

Autobahn