aiohttp is vulnerable to Improper Input Validation
37
Low Risk
The WebSocket client accepts and decompresses frames that have the RSV1 (compressed) bit set even when the permessage-deflate extension was not negotiated. A peer can therefore force decompression of frames on a connection where compression was explicitly opted out. This can cause additional CPU and memory consumption while inflating attacker-supplied payloads. The fix rejects compressed frames when permessage-deflate was not negotiated.
You are affected if you are using a version that falls within the vulnerable range.
aiohttp is vulnerable to Improper Input Validation in versions 0.0.1 - 3.14.1.
Upgrade the aiohttp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant