THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-70646 (HIGH 7.5) — aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMAC signature. This allows an unauthenticated attacker to force expensive parsing of arbitrary JSON pa

[NVD] CVE-2026-70646 (HIGH 7.5) — aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMAC signature. This allows an unauthenticated attacker to force expensive parsing of arbitrary JSON pa

mednvdPublished 2026-08-06

CVE-2026-70646 CVSS: 7.5 HIGH Published: 2026-08-06T15:17:27.750

aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMAC signature. This allows an unauthenticated attacker to force expensive parsing of arbitrary JSON payloads that will ultimately be rejected, leading to un

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-70646