Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94397.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-94397
Upstream
Published
2026-07-30T19:18:33Z
Modified
2026-08-30T05:24:52Z
Summary
CVE-2026-59881 affecting package python-aiohttp 3.6.2-3
Details

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client accepts and decompresses frames with the RSV1 bit set even when the permessage-deflate extension was not negotiated, allowing a malicious server to cause unexpected CPU and memory consumption. This issue is fixed in version 3.14.2.

References

Affected packages

Azure Linux:3 / python-aiohttp

Package

Name
python-aiohttp
Purl
pkg:rpm/azure-linux/python-aiohttp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
3.6.2-3

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94397.json"