Количество 4
Количество 4
CVE-2026-59881
(AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...)
CVE-2026-59881
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client accepts and decompresses frames with the RSV1 bit set even when the permessage-deflate extension was not negotiated, allowing a malicious server to cause unexpected CPU and memory consumption. This issue is fixed in version 3.14.2.
CVE-2026-59881
AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...
GHSA-mq44-7p77-q5h7
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-59881 (AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...) | 0% Низкий | 7 дней назад | ||
CVE-2026-59881 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client accepts and decompresses frames with the RSV1 bit set even when the permessage-deflate extension was not negotiated, allowing a malicious server to cause unexpected CPU and memory consumption. This issue is fixed in version 3.14.2. | 0% Низкий | 7 дней назад | ||
CVE-2026-59881 AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ... | 0% Низкий | 7 дней назад | ||
GHSA-mq44-7p77-q5h7 AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate | 0% Низкий | 3 дня назад |
Уязвимостей на страницу