CVE-2026-59881

AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client accepts and decompresses frames with the RSV1 bit set even when the permessage-deflate extension was not negotiated, allowing a malicious server to cause unexpected CPU and memory consumption. This issue is fixed in version 3.14.2.


We have discovered 299 live websites that are affected by CVE-2026-59881.

Run a Free Instant Scan




Affected Software

Product  AIOHTTP
Category Miscellaneous
Vulnerable Domains299 live websites (100% of AIOHTTP install base)
Vulnerable Versions
  • from 0 through 3.14.2
Vulnerable Versions Count18 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-20 Improper Input Validation



Details

  • Published - Jul 30, 2026
  • Updated - Jul 30, 2026

Website Distribution by Country

Number of websites using CVE-2026-59881
United States124 websites



Germany84 websites
Singapore15 websites
Finland12 websites
Russia10 websites
GB8 websites
India7 websites
China4 websites
France4 websites

Website Distribution by TLD

Number of websites using CVE-2026-59881
.com120 websites
.fi31 websites
.net20 websites
.de18 websites
.org12 websites
.ru7 websites
.ca7 websites
.info6 websites
.co.uk6 websites
.io6 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-59881

Top websites that are affected by CVE-2026-59881. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.org United States**,***
*********.com Germany**,***
******.*****.fi United States***,***
******************.de Germany***,***
*****.************.org United States***,***
****.al United States***,***
******.************.fi United States***,***
*******************.com Germany***,***
****.bz United States***,***
****.lc United States***,***
See full domain list

FAQ

CVE-2026-59881 is Improper Input Validation in AIOHTTP
A total of 299 websites have been identified as vulnerable to CVE-2026-59881, based on global website indexing conducted by WebTechSurvey.
The AIOHTTP is affected by the CVE-2026-59881 vulnerability.
AIOHTTP versions up to 3.14.2 are vulnerable to CVE-2026-59881.
CVE-2026-59881 is resolved in version 3.14.2 of AIOHTTP.