{"id":"CVE-2026-59881","title":"aiohttp: AIOHTTP: Denial of Service via unnegotiated WebSocket compression (CVE-2026-59881)","summary":"A flaw was found in AIOHTTP. The WebSocket client in AIOHTTP processes compressed data frames even when the compression mechanism, known as permessage-deflate, has not been properly negotiated. A malicious server can exploit this by sendin…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cvssSource":"vendor","cwe":["CWE-409","CWE-20"],"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","affected":["exploit_intelligence","lightspeed_core","migration_toolkit_for_applications 8","openshift_lightspeed","ai_inference_server","ansible_automation_platform 2","ansible_automation_platform_ansible_core 2","discovery 2","enterprise_linux 10","enterprise_linux 9","enterprise_linux_ai_rhel_ai 3","openshift_ai_rhoai","satellite 6","update_infrastructure_4_for_cloud_providers","update_infrastructure 5","ai_inference_server 3.4"],"patched":["ai_inference_server 3.4"],"published":"2026-07-30","updated":"2026-09-24","sourceUpdated":"2026-09-24T06:06:42+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59881.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59881.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-59881"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2509545"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-59881"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59881"},{"url":"http://github.com/aio-libs/aiohttp/releases/tag/v3.14.2"},{"url":"https://github.com/aio-libs/aiohttp/commit/47fb6ae354d4fa22048f4dbe7dbf82b625f0a2f6"},{"url":"https://github.com/aio-libs/aiohttp/pull/12978"},{"url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mq44-7p77-q5h7"},{"url":"https://access.redhat.com/errata/RHSA-2026:70965"},{"url":"https://access.redhat.com/errata/RHSA-2026:70979"},{"url":"https://access.redhat.com/errata/RHSA-2026:70995"},{"url":"https://access.redhat.com/errata/RHSA-2026:70969"},{"url":"https://github.com/aio-libs/aiohttp"},{"url":"https://github.com/advisories/GHSA-mq44-7p77-q5h7"}],"tags":["csaf","vex","red-hat","osv","pip","ghsa"],"epss":0.00524,"epssPercentile":0.42005,"aliases":["GHSA-mq44-7p77-q5h7","PYSEC-2026-3547"],"ecosystem":"pip","ingestedAt":"2026-08-03T21:30:01.604Z","slug":"CVE-2026-59881","body":"## Overview\n\nA flaw was found in AIOHTTP. The WebSocket client in AIOHTTP processes compressed data frames even when the compression mechanism, known as permessage-deflate, has not been properly negotiated. A malicious server can exploit this by sending specially crafted compressed frames. This can lead to unexpected and excessive consumption of the system's central processing unit (CPU) and memory, potentially resulting in a denial of service (DoS) for legitimate users.\n\n## Vendor advisories\n\n- **RHSA-2026:70965** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70965)\n- **RHSA-2026:70979** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70979)\n- **RHSA-2026:70995** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70995)\n- **RHSA-2026:70969** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70969)\n- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Lightspeed Core, Migration Toolkit for Applications 8, OpenShift Lightspeed, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, … · no fix planned: Exploit Intelligence, Lightspeed Core, Migration Toolkit for Applications 8, OpenShift Lightspeed, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59881.json)\n\n**aiohttp: AIOHTTP: Denial of Service via unnegotiated WebSocket compression** — rated Moderate by Red Hat. Released 2026-07-30, updated 2026-09-24.\n\nAffected:\n\n- Exploit Intelligence\n- Lightspeed Core\n- Migration Toolkit for Applications 8\n- OpenShift Lightspeed\n- Red Hat AI Inference Server\n- Red Hat Ansible Automation Platform 2\n- Red Hat Ansible Automation Platform Ansible Core 2\n- Red Hat Discovery 2\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat Satellite 6\n- Red Hat Update Infrastructure 4 for Cloud Providers\n- Red Hat Update Infrastructure 5\n\nFixed:\n\n- Red Hat AI Inference Server 3.4\n\nNo fix planned:\n\n- Exploit Intelligence\n- Lightspeed Core\n- Migration Toolkit for Applications 8\n- OpenShift Lightspeed\n- Red Hat AI Inference Server\n- Red Hat Ansible Automation Platform 2\n- Red Hat Ansible Automation Platform Ansible Core 2\n- Red Hat Discovery 2\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat Satellite 6\n- Red Hat Update Infrastructure 4 for Cloud Providers\n- Red Hat Update Infrastructure 5\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat Hardened Images\n\n## Remediation\n\nFor more information visit https://access.redhat.com/errata/RHSA-2026:70965 https://access.redhat.com/errata/RHSA-2026:70965\nFor more information visit https://access.redhat.com/errata/RHSA-2026:70979 https://access.redhat.com/errata/RHSA-2026:70979\nFor more information visit https://access.redhat.com/errata/RHSA-2026:70995 https://access.redhat.com/errata/RHSA-2026:70995\n\nWorkarounds / mitigations:\n\n- For deployments where upgrading is not immediately possible, ensure that aiohttp WebSocket clients only connect to trusted servers. The vulnerability requires the client to have opted out of permessage-deflate compression and the server to send RSV1-flagged frames, so connections using default compression settings are less likely to trigger this issue.\n\n## Package advisory (CVE-2026-59881)\n\nAffected packages:\n\n- `aiohttp < 3.14.2`\n\nPatched in:\n\n- `aiohttp 3.14.2`\n\nSource: https://osv.dev/vulnerability/GHSA-mq44-7p77-q5h7","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":209983,"id":"CVE-2026-59881","ts":1790235612972,"field":"cvss","old":null,"new":"5.3"}]}