Input validation error in aiohttp - #VU133989
Published: June 9, 2026
aiohttp
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in websocket frame payload handling when processing large incomplete websocket frame payloads. A remote attacker can send large incomplete websocket frame payloads to cause a denial of service.
The issue can bypass the usual size limits on memory use.