THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-mq44-7p77-q5h7 (medium) — AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate

[GHSA] GHSA-mq44-7p77-q5h7 (medium) — AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate

highgithub_advisoriesPublished 2026-08-03

GHSA-mq44-7p77-q5h7 Severity: medium CVE: CVE-2026-59881

AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate

### Summary

The client accepts and decompresses frames with the RSV1 bit set even when the `permessage-deflate` extension was not negotiated.

### Impact

A client may unexpectedly decompress WebSocket frames when explicitly opted out. This could lea

Indicators of compromise

Original source: https://github.com/advisories/GHSA-mq44-7p77-q5h7