Impact
Autobahn Python implements WebSocket’s permessage-deflate extension by checking the compressed frame size before inflating it. The flaw is that after inflation the library does not re‑validate the decompressed message against the configured maxMessagePayloadSize. As a result, a remote client can send a compressed frame that is within the allowed wire‑size but expands beyond the application limit, causing the server to allocate large buffers, concatenate the data, and pass it to application callbacks. This logic flaw can lead to significant resource exhaustion; the advisory states it does not affect confidentiality or integrity.
Affected Systems
The issue exists in Autobahn Python releases prior to 26.7.1 and is reported for the crossbario:autobahn-python product. All versions before 26.7.1 that accept permessage‑deflate without re‑checking the inflated size are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a remote unauthenticated client sending a specially crafted compressed frame; this can trigger memory pressure and potential denial of service. No direct impact on confidentiality or integrity is established. The vulnerability is exploitable without special privileges, and the risk is primarily in the availability domain.
OpenCVE Enrichment
Github GHSA