PT-2026-95665 · Pypi · Autobahn
CVE-2026-77528
·
Published
2026-09-18
·
Updated
2026-10-01
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Autobahn Python versions prior to 26.7.1
Description
WebSocket endpoints that accept permessage-deflate and rely on
maxMessagePayloadSize enforce the limit against the compressed frame length before inflation but fail to recheck the decompressed message size before delivery. A remote unauthenticated client can send a valid compressed frame that remains below the configured wire-size limit but expands beyond the application message limit upon decompression. This leads to the allocation, joining, and validation of oversized data passed to application callbacks, which can result in resource-exhaustion pressure.Recommendations
Update to version 26.7.1.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Autobahn