THREAT OPS › Threat News › [NVD] CVE-2026-70646 (HIGH 7.5) — aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMAC signature. This allows an unauthenticated attacker to force expensive parsing of arbitrary JSON pa
[NVD] CVE-2026-70646 (HIGH 7.5) — aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMAC signature. This allows an unauthenticated attacker to force expensive parsing of arbitrary JSON pa
CVE-2026-70646 CVSS: 7.5 HIGH Published: 2026-08-06T15:17:27.750
aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMAC signature. This allows an unauthenticated attacker to force expensive parsing of arbitrary JSON payloads that will ultimately be rejected, leading to un
Indicators of compromise
- CVE-2026-70646cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-70646