Threats Tagged 'cve-2026-59881'
View all threats tagged with 'cve-2026-59881'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-59881'
Click on any threat for detailed analysis and mitigation recommendations
0 A security update for python-aiohttp addresses three vulnerabilities: CVE-2026-59881, which involves excessive resource consumption due to accepting compressed WebSocket frames without negotiation; CVE-2026-69243, an HTTP request smuggling vulnerability via the WebSocket upgrade procedure; and CVE-2026-69244, an out-of-bounds heap read in the C response parser triggered by malformed responses. These issues could impact the stability and security of applications using python-aiohttp. The update fixes these vulnerabilities to prevent potential exploitation. Join the discussion | GCVE Database | 08/30/2026, 14:37:24 UTC Added: 09/17/2026, 01:58:54 UTC |
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client accepts and decompresses frames with the RSV1 bit set even when the permessage-deflate extension was not negotiated, allowing a malicious server to cause unexpected CPU and memory consumption. This issue is fixed in version 3.14.2. Join the discussion | CVE Database V5 | 07/30/2026, 17:34:32 UTC Added: 07/30/2026, 17:53:47 UTC |
Showing 1 to 2 of 2 results