Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59881

Опубликовано: 30 июл. 2026
Источник: nvd
EPSS Низкий

Описание

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client accepts and decompresses frames with the RSV1 bit set even when the permessage-deflate extension was not negotiated, allowing a malicious server to cause unexpected CPU and memory consumption. This issue is fixed in version 3.14.2.

EPSS

Процентиль: 22%
0.00302
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
7 дней назад

(AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...)

debian
7 дней назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

github
3 дня назад

AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate

EPSS

Процентиль: 22%
0.00302
Низкий

Дефекты

CWE-20