CVE-2026-77528: Crossbario Autobahn-Python

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio. Prior to 26.7.1, WebSocket endpoints that accept permessage-deflate and rely on maxMessagePayloadSize enforce that limit against the compressed frame length before inflation but do not recheck the decompressed message size before delivery. A remote unauthenticated client can send a valid compressed frame below the configured wire-size limit that expands beyond the application message limit, causing oversized data to be allocated, joined, validated, and passed to application callbacks. This can create resource-exhaustion pressure, but the advisory does not establish confidentiality or integrity impact. This issue is fixed in version 26.7.1.

Affected products

  • Crossbario Autobahn-Python: before 26.7.1 (fixed in 26.7.1)

Published 2026-09-18. Last modified 2026-09-24.