AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client accepts and decompresses frames with the RSV1 bit set even when the permessage-deflate extension was not negotiated, allowing a malicious server to cause unexpected CPU and memory consumption. This issue is fixed in version 3.14.2.
We have discovered 299 live websites that are affected by CVE-2026-59881.
| Product | |
| Category | Miscellaneous |
| Vulnerable Domains | 299 live websites (100% of AIOHTTP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 18 versions ( 100% of all versions) |
| 124 websites | |
| 84 websites | |
| 15 websites | |
| 12 websites | |
| 10 websites | |
| 8 websites | |
| 7 websites | |
| 4 websites | |
| 4 websites |
| .com | 120 websites |
| .fi | 31 websites |
| .net | 20 websites |
| .de | 18 websites |
| .org | 12 websites |
| .ru | 7 websites |
| .ca | 7 websites |
| .info | 6 websites |
| .co.uk | 6 websites |
| .io | 6 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ************.org | **,*** | ||
| *********.com | **,*** | ||
| ******.*****.fi | ***,*** | ||
| ******************.de | ***,*** | ||
| *****.************.org | ***,*** | ||
| ****.al | ***,*** | ||
| ******.************.fi | ***,*** | ||
| *******************.com | ***,*** | ||
| ****.bz | ***,*** | ||
| ****.lc | ***,*** |
FAQ