{"id":"CVE-2026-77528","title":"Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio","summary":"Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio. Prior to 26.7.1, WebSocket endpoints that accept permessage-deflate and rely on maxMessagePayloadSize enforce that limit against the com…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-409","CWE-770"],"vendor":"crossbario","product":"autobahn-python","affected":["autobahn-python < 26.7.1"],"published":"2026-09-18","updated":"2026-09-19","sourceUpdated":"2026-09-19T15:17:02.063","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-77528","references":[{"url":"https://github.com/crossbario/autobahn-python/commit/77d323a30b09b1828ad8be2ce6344e056970e613","label":"security-advisories@github.com"},{"url":"https://github.com/crossbario/autobahn-python/pull/1916","label":"security-advisories@github.com"},{"url":"https://github.com/crossbario/autobahn-python/releases/tag/v26_7_1","label":"security-advisories@github.com"},{"url":"https://github.com/crossbario/autobahn-python/security/advisories/GHSA-hxp9-w8x3-p566","label":"security-advisories@github.com"}],"tags":["nvd","cve.org"],"epss":0.00401,"epssPercentile":0.34042,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-19T13:37:22.821549Z"},"ingestedAt":"2026-09-18T19:49:30.586Z","slug":"CVE-2026-77528","body":"## Overview\n\nAutobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio. Prior to 26.7.1, WebSocket endpoints that accept permessage-deflate and rely on maxMessagePayloadSize enforce that limit against the compressed frame length before inflation but do not recheck the decompressed message size before delivery. A remote unauthenticated client can send a valid compressed frame below the configured wire-size limit that expands beyond the application message limit, causing oversized data to be allocated, joined, validated, and passed to application callbacks. This can create resource-exhaustion pressure, but the advisory does not establish confidentiality or integrity impact. This issue is fixed in version 26.7.1.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}