---
id: CVE-2026-59881
title: >-
  aiohttp: AIOHTTP: Denial of Service via unnegotiated WebSocket compression
  (CVE-2026-59881)
summary: >-
  A flaw was found in AIOHTTP. The WebSocket client in AIOHTTP processes
  compressed data frames even when the compression mechanism, known as
  permessage-deflate, has not been properly negotiated. A malicious server can
  exploit this by sendin…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cvssSource: vendor
cwe:
  - CWE-409
  - CWE-20
vendor: Red Hat
product: Red Hat OpenShift AI (RHOAI)
affected:
  - exploit_intelligence
  - lightspeed_core
  - migration_toolkit_for_applications 8
  - openshift_lightspeed
  - ai_inference_server
  - ansible_automation_platform 2
  - ansible_automation_platform_ansible_core 2
  - discovery 2
  - enterprise_linux 10
  - enterprise_linux 9
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai_rhoai
  - satellite 6
  - update_infrastructure_4_for_cloud_providers
  - update_infrastructure 5
  - ai_inference_server 3.4
patched:
  - ai_inference_server 3.4
published: '2026-07-30'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T06:06:42+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59881.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59881.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-59881'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2509545'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-59881'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59881'
  - url: 'http://github.com/aio-libs/aiohttp/releases/tag/v3.14.2'
  - url: >-
      https://github.com/aio-libs/aiohttp/commit/47fb6ae354d4fa22048f4dbe7dbf82b625f0a2f6
  - url: 'https://github.com/aio-libs/aiohttp/pull/12978'
  - url: >-
      https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mq44-7p77-q5h7
  - url: 'https://access.redhat.com/errata/RHSA-2026:70965'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70979'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70995'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70969'
  - url: 'https://github.com/aio-libs/aiohttp'
  - url: 'https://github.com/advisories/GHSA-mq44-7p77-q5h7'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
  - ghsa
epss: 0.00524
epssPercentile: 0.42005
aliases:
  - GHSA-mq44-7p77-q5h7
  - PYSEC-2026-3547
ecosystem: pip
ingestedAt: '2026-08-03T21:30:01.604Z'
---

## Overview

A flaw was found in AIOHTTP. The WebSocket client in AIOHTTP processes compressed data frames even when the compression mechanism, known as permessage-deflate, has not been properly negotiated. A malicious server can exploit this by sending specially crafted compressed frames. This can lead to unexpected and excessive consumption of the system's central processing unit (CPU) and memory, potentially resulting in a denial of service (DoS) for legitimate users.

## Vendor advisories

- **RHSA-2026:70965** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70965)
- **RHSA-2026:70979** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70979)
- **RHSA-2026:70995** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70995)
- **RHSA-2026:70969** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70969)
- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Lightspeed Core, Migration Toolkit for Applications 8, OpenShift Lightspeed, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, … · no fix planned: Exploit Intelligence, Lightspeed Core, Migration Toolkit for Applications 8, OpenShift Lightspeed, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59881.json)

**aiohttp: AIOHTTP: Denial of Service via unnegotiated WebSocket compression** — rated Moderate by Red Hat. Released 2026-07-30, updated 2026-09-24.

Affected:

- Exploit Intelligence
- Lightspeed Core
- Migration Toolkit for Applications 8
- OpenShift Lightspeed
- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Red Hat Ansible Automation Platform Ansible Core 2
- Red Hat Discovery 2
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat Satellite 6
- Red Hat Update Infrastructure 4 for Cloud Providers
- Red Hat Update Infrastructure 5

Fixed:

- Red Hat AI Inference Server 3.4

No fix planned:

- Exploit Intelligence
- Lightspeed Core
- Migration Toolkit for Applications 8
- OpenShift Lightspeed
- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Red Hat Ansible Automation Platform Ansible Core 2
- Red Hat Discovery 2
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat Satellite 6
- Red Hat Update Infrastructure 4 for Cloud Providers
- Red Hat Update Infrastructure 5

Not affected:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat Hardened Images

## Remediation

For more information visit https://access.redhat.com/errata/RHSA-2026:70965 https://access.redhat.com/errata/RHSA-2026:70965
For more information visit https://access.redhat.com/errata/RHSA-2026:70979 https://access.redhat.com/errata/RHSA-2026:70979
For more information visit https://access.redhat.com/errata/RHSA-2026:70995 https://access.redhat.com/errata/RHSA-2026:70995

Workarounds / mitigations:

- For deployments where upgrading is not immediately possible, ensure that aiohttp WebSocket clients only connect to trusted servers. The vulnerability requires the client to have opted out of permessage-deflate compression and the server to send RSV1-flagged frames, so connections using default compression settings are less likely to trigger this issue.

## Package advisory (CVE-2026-59881)

Affected packages:

- `aiohttp < 3.14.2`

Patched in:

- `aiohttp 3.14.2`

Source: https://osv.dev/vulnerability/GHSA-mq44-7p77-q5h7
