The client accepts and decompresses frames with the RSV1 bit set even when the permessage-deflate extension was not negotiated.
A client may unexpectedly decompress WebSocket frames when explicitly opted out. This could lead to additional CPU/memory consumption, but is unlikely to be a significant issue unless a zip bomb vulnerability or similar is also present.
Patch: https://github.com/aio-libs/aiohttp/commit/47fb6ae354d4fa22048f4dbe7dbf82b625f0a2f6
{
"cwe_ids": [
"CWE-20"
],
"github_reviewed": true,
"github_reviewed_at": "2026-08-03T20:40:55Z",
"nvd_published_at": "2026-07-30T19:18:33Z",
"severity": "MODERATE"
}