Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xcgm-r5h9-7989

Опубликовано: 15 июн. 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.6

Описание

aiohttp: Incomplete websocket frame payloads bypass memory limits

Summary

If an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual size limits on memory use.

Impact

If a web application has WebSocket endpoints, it may be possible for an attacker to execute a DoS attack through excessive memory use.


Patch: https://github.com/aio-libs/aiohttp/commit/14b6ee851fb16ec199acb950de0c82d476799e7d

Пакеты

Наименование

aiohttp

pip
Затронутые версииВерсия исправления

<= 3.14.0

3.14.1

EPSS

Процентиль: 23%
0.00305
Низкий

6.6 Medium

CVSS4

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual size limits on memory use. This vulnerability is fixed in 3.14.1.

CVSS3: 5.9
redhat
около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual size limits on memory use. This vulnerability is fixed in 3.14.1.

CVSS3: 7.5
nvd
около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual size limits on memory use. This vulnerability is fixed in 3.14.1.

CVSS3: 7.5
debian
около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

suse-cvrf
18 дней назад

Security update for python-aiohttp

EPSS

Процентиль: 23%
0.00305
Низкий

6.6 Medium

CVSS4

Дефекты

CWE-770