{"id":"CVE-2026-59881","aliases":["GHSA-mq44-7p77-q5h7","PYSEC-2026-3547"],"url":"https://o3.security/vulnerability/CVE-2026-59881","summary":"AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate","details":"AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client accepts and decompresses frames with the RSV1 bit set even when the permessage-deflate extension was not negotiated, allowing a malicious server to cause unexpected CPU and memory consumption. This issue is fixed in version 3.14.2.","published":"2026-07-30T17:34:32.415Z","modified":"2026-09-14T18:26:58.793792938Z","cvss":null,"epss":{"score":0.00302,"percentile":0.22922,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"aiohttp","fixedVersion":"3.14.2"}],"fix":{"url":"https://github.com/aio-libs/aiohttp/commit/47fb6ae354d4fa22048f4dbe7dbf82b625f0a2f6","label":"aio-libs/aiohttp@47fb6ae"},"references":[{"type":"WEB","url":"http://github.com/aio-libs/aiohttp/releases/tag/v3.14.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59881.json"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mq44-7p77-q5h7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59881"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/commit/47fb6ae354d4fa22048f4dbe7dbf82b625f0a2f6"},{"type":"FIX","url":"https://github.com/aio-libs/aiohttp/pull/12978"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-14T18:26:58.793792938Z"}}