VDB
CVE-2026-59881
CVE-2026-59881
PUBLISHED
CVSS 6.9 MEDIUM
Reported by GitHub_M · Published July 30, 2026
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client accepts and decompresses frames with the RSV1 bit set even when the permessage-deflate extension was not negotiated, allowing a malicious server to cause unexpected CPU and memory consumption. This issue is fixed in version 3.14.2.
Risk Scores
CVSS 4.0
6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| aio-libs | aiohttp | < 3.14.2 |
| chainguard | py3.13-scanner-test-libraries-aiohttp | 0, 0, 0 |
| chainguard | airflow-core-2 | 0, 0, 0 |
| wolfi | py3-cassandra-medusa | 0, 0, 0 |
| chainguard | apache-beam-python-3.11-sdk | 0, 0, 0 |
| wolfi | kserve | 0, 0, 0 |
| chainguard | text-generation-inference | 0, 0 |
| chainguard | py3-cassandra-medusa | 0, 0, 0 |
| chainguard | dask-kubernetes | 0, 0, 0 |
| chainguard | kserve-models-web-app | 0, 0, 0 |
| chainguard | dask-kubernetes-fips | 0 |
| chainguard | kserve | 0, 0, 0 |
| chainguard | puppygraph-python | 0, 0, 0 |
| chainguard | apache-beam-python-3.12-sdk | 0, 0, 0 |
| chainguard | lmcache-cuda-12.8 | 0 |
| chainguard | apache-beam-python-3.13-sdk | 0, 0, 0 |
| chainguard | datahub-ingestion-fips | 0 |
| chainguard | airflow-3 | 0, 0, 0 |
| wolfi | open-webui | 0, 0, 0 |
| chainguard | open-webui | 0 |
…and 4 more
Timeline
- Jul 30, 2026 CVE Published
- Jul 30, 2026 CVE Updated
- Jul 31, 2026 Coalition ESS Score
- Aug 3, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
References
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mq44-7p77-q5h7 x_refsource_CONFIRM
- https://github.com/aio-libs/aiohttp/pull/12978 x_refsource_MISC
- https://github.com/aio-libs/aiohttp/commit/47fb6ae354d4fa22048f4dbe7dbf82b625f0a2f6 x_refsource_MISC
- http://github.com/aio-libs/aiohttp/releases/tag/v3.14.2 x_refsource_MISC