CVE-2026-59881

Aliases:GHSA-mq44-7p77-q5h7PYSEC-2026-3547UBUNTU-CVE-2026-59881DEBIAN-CVE-2026-59881CGA-342c-5jrv-9x95CGA-7v29-7h5c-ccxxCGA-825h-f4m4-ppfjCGA-9m67-5ch9-3q58CGA-f4g8-w248-cp3fCGA-f7gc-5phg-q29wCGA-hpw9-fg9w-7m7xCGA-m3gw-fj2g-v975CGA-mfp9-fr5c-9p24CGA-29mv-55p9-xm65CGA-29w2-5c5h-9j2vCGA-2cch-r3p5-vfwfCGA-3rrg-386v-mm24CGA-445x-3cmq-j5f8CGA-46m5-3c2x-qfh2CGA-4f6w-gwjv-72j8CGA-5c22-vm23-rqmmCGA-5qx6-gvq8-rvj5CGA-6428-x58q-5x8hCGA-65mq-m7xc-gvvjCGA-6hj9-v267-8fcvCGA-6v86-9p6x-h526CGA-6vqx-vmmq-7frwCGA-7gwp-5rhr-m3g7CGA-8fgm-f2rv-vvwrCGA-8wgc-qvxf-fpq9CGA-fxwj-p5gx-gxrhCGA-gfv2-3w68-r973CGA-h66w-qmjp-grppCGA-hhm9-98g4-7m88CGA-j8x4-38rr-hhw2CGA-jq87-xqh6-9j2cCGA-jw3g-wjqx-rrp7CGA-mg8x-4mgq-3c3qCGA-p78m-qc83-79cpCGA-qq39-x977-3j3jCGA-qvpj-wwx4-q5c3CGA-r7x5-jhm4-pg52CGA-vm54-7f85-4698CGA-wh5v-vpr2-c5f4CGA-x57g-2jmp-6jv2CGA-xvrp-c57h-v8xjCGA-2x8f-vqqw-82qxCGA-hr3c-5jg5-ff89CGA-rq6f-f266-9748CGA-vf5m-h4v7-xcp4
Deferred
Published: 30 Jul 2026, 17:34
Last modified:30 Jul 2026, 18:35

Vulnerability Summary

Overall Risk (default)
medium
28/100
CVSS Score
6.9 MEDIUM
v4.0 (cve.org)
EPSS Score
0.3% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Jul 2026, 17:34
Published
Vulnerability first disclosed
30 Jul 2026, 18:35
Last Modified
Vulnerability information updated

Description

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client accepts and decompresses frames with the RSV1 bit set even when the permessage-deflate extension was not negotiated, allowing a malicious server to cause unexpected CPU and memory consumption. This issue is fixed in version 3.14.2.

CVSS Metrics

  • v4.0MEDIUMScore: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  • v4.0MEDIUMScore: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS Trends

Current EPSS score: 0.30% Percentile: 23%

Techniques & Countermeasures

  • CWE-20Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Affected Systems

  • aio-libsaiohttp

    < 3.14.2

  • chainguardairflow-2

    all

  • chainguardairflow-3

    < 3.3.1-r1 | < 3.3.0-r4

  • chainguardairflow-3-iamguarded-compat

    all

  • chainguardairflow-core-2

    < 2.11.2-r6

  • chainguardapache-beam-python-3.11-sdk

    < 2.75.0-r2

  • chainguardapache-beam-python-3.12-sdk

    < 2.75.0-r1

  • chainguardapache-beam-python-3.13-sdk

    < 2.75.0-r2

  • chainguardawx

    < 24.6.1-r49

  • chainguarddask-kubernetes

    < 2026.3.0-r11

  • chainguarddask-kubernetes-fips

    < 2026.3.0-r6 | < 2026.3.0-r5

  • chainguarddatahub-ingestion-fips

    < 1.6.0-r9

  • chainguardkserve

    < 0.20.0-r7

  • chainguardkserve-localmodel

    < 0.20.0-r7

  • chainguardkserve-models-web-app

    < 1.0.1-r2

  • chainguardkserve-storage-controller

    < 0.19.0-r5 | all | < 0.20.0-r7

  • chainguardlmcache-cuda-12.8

    < 0.5.3-r0

  • chainguardopen-webui

    < 0.11.0-r6

  • chainguardpuppygraph-python

    < 0.1.6-r2

  • chainguardpy3-cassandra-medusa

    < 0.29.1-r1

  • chainguardpy3.10-vllm-cuda-12.4

    < 0.18.1-r7

  • chainguardpy3.12-vllm-cuda-12.4

    < 0.18.1-r7

  • chainguardpy3.13-scanner-test-libraries-aiohttp

    < 0.0.1-r4

  • chainguardtext-generation-inference

    < 3.3.7-r23

  • chainguardtritonserver-backend-vllm-cuda-13.0

    < 25.11-r11

  • wolfiairflow-3

    < 3.3.1-r1 | < 3.3.0-r4

  • wolfiairflow-3-iamguarded-compat

    all

  • wolfidask-kubernetes

    < 2026.3.0-r11

  • wolfikserve

    < 0.20.0-r7

  • wolfikserve-localmodel

    < 0.20.0-r7

  • wolfikserve-storage-controller

    < 0.19.0-r5 | all | < 0.20.0-r7

  • wolfiopen-webui

    < 0.11.0-r6

  • wolfipy3-cassandra-medusa

    < 0.29.1-r1

  • debianpython-aiohttp

    all | all | all | all

  • ubuntupython-aiohttp

    all

  • PyPIaiohttp

    < 3.14.2

References (12)