THREAT OPS › Threat News › [GHSA] GHSA-mq44-7p77-q5h7 (medium) — AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
[GHSA] GHSA-mq44-7p77-q5h7 (medium) — AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
GHSA-mq44-7p77-q5h7 Severity: medium CVE: CVE-2026-59881
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
### Summary
The client accepts and decompresses frames with the RSV1 bit set even when the `permessage-deflate` extension was not negotiated.
### Impact
A client may unexpectedly decompress WebSocket frames when explicitly opted out. This could lea
Indicators of compromise
- 47fb6ae354d4fa22048f4dbe7dbf82b625f0a2f6sha1
- CVE-2026-59881cve
Original source: https://github.com/advisories/GHSA-mq44-7p77-q5h7