What is CVE-2026-59881?
CVE-2026-59881 affects the WebSocket client in the aiohttp framework. A malicious server can send compressed frames with the RSV1 bit set even when the permessage-deflate extension was not negotiated, leading to excessive CPU and memory consumption. Affected users should upgrade to version 3.14.2 or later.
Azərbaycanca: CVE-2026-59881 aiohttp framework-də WebSocket müştəri komponentinə aiddir. Zərərli server, permessage-deflate genişlənməsi razılaşdırılmadığı halda belə, RSV1 bit dəsti ilə sıxılmış çərçivələr göndərərək yüksək CPU və yaddaş istifadəsinə səbəb ola bilər. Təsirə məruz qalan istifadəçilər dərhal 3.14.2 versiyasına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which component of aiohttp does CVE-2026-59881 affect?
This vulnerability affects the WebSocket client component in the aiohttp framework.
How does a malicious server cause resource consumption when permessage-deflate is not negotiated?
A malicious server can send compressed frames with the RSV1 bit set, leading to excessive CPU and memory consumption.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.