Description
Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio. Prior to 26.7.1, WebSocket endpoints that accept permessage-deflate and rely on maxMessagePayloadSize enforce that limit against the compressed frame length before inflation but do not recheck the decompressed message size before delivery. A remote unauthenticated client can send a valid compressed frame below the configured wire-size limit that expands beyond the application message limit, causing oversized data to be allocated, joined, validated, and passed to application callbacks. This can create resource-exhaustion pressure, but the advisory does not establish confidentiality or integrity impact. This issue is fixed in version 26.7.1.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Resource Exhaustion
Action: Patch
AI Analysis

Impact

Autobahn Python implements WebSocket’s permessage-deflate extension by checking the compressed frame size before inflating it. The flaw is that after inflation the library does not re‑validate the decompressed message against the configured maxMessagePayloadSize. As a result, a remote client can send a compressed frame that is within the allowed wire‑size but expands beyond the application limit, causing the server to allocate large buffers, concatenate the data, and pass it to application callbacks. This logic flaw can lead to significant resource exhaustion; the advisory states it does not affect confidentiality or integrity.

Affected Systems

The issue exists in Autobahn Python releases prior to 26.7.1 and is reported for the crossbario:autobahn-python product. All versions before 26.7.1 that accept permessage‑deflate without re‑checking the inflated size are vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. EPSS is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a remote unauthenticated client sending a specially crafted compressed frame; this can trigger memory pressure and potential denial of service. No direct impact on confidentiality or integrity is established. The vulnerability is exploitable without special privileges, and the risk is primarily in the availability domain.

Generated by OpenCVE AI on September 19, 2026 at 11:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Autobahn Python to version 26.7.1 or later.
  • Set process resource limits (e.g., ulimit for memory or rlimits in a container) to constrict the maximum memory a connection can consume.
  • Monitor application memory and CPU usage for abnormal spikes that may indicate exploitation attempts.

Generated by OpenCVE AI on September 19, 2026 at 11:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-hxp9-w8x3-p566 Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation
History

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Crossbario
Crossbario autobahn-python
Vendors & Products Crossbario
Crossbario autobahn-python

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio. Prior to 26.7.1, WebSocket endpoints that accept permessage-deflate and rely on maxMessagePayloadSize enforce that limit against the compressed frame length before inflation but do not recheck the decompressed message size before delivery. A remote unauthenticated client can send a valid compressed frame below the configured wire-size limit that expands beyond the application message limit, causing oversized data to be allocated, joined, validated, and passed to application callbacks. This can create resource-exhaustion pressure, but the advisory does not establish confidentiality or integrity impact. This issue is fixed in version 26.7.1.
Title Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation
Weaknesses CWE-409
CWE-770
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Crossbario Autobahn-python
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-19T14:11:38.071Z

Reserved: 2026-08-20T20:23:02.508Z

Link: CVE-2026-77528

cve-icon Vulnrichment

Updated: 2026-09-19T14:04:25.831Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T20:17:22.830

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-77528

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:28:26Z

Weaknesses
  • CWE-409

    Improper Handling of Highly Compressed Data (Data Amplification)

  • CWE-770

    Allocation of Resources Without Limits or Throttling