Improper Handling of Highly Compressed Data (Data Amplification) Affecting awx package, versions <24.6.1-r57


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.52% (42nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-AWX-20066496
  • published23 Sept 2026
  • disclosed18 Sept 2026

Introduced: 18 Sep 2026

NewCVE-2026-77528  (opens in a new tab)
CWE-409  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade Chainguard awx to version 24.6.1-r57 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream awx package and not the awx package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio. Prior to 26.7.1, WebSocket endpoints that accept permessage-deflate and rely on maxMessagePayloadSize enforce that limit against the compressed frame length before inflation but do not recheck the decompressed message size before delivery. A remote unauthenticated client can send a valid compressed frame below the configured wire-size limit that expands beyond the application message limit, causing oversized data to be allocated, joined, validated, and passed to application callbacks. This can create resource-exhaustion pressure, but the advisory does not establish confidentiality or integrity impact. This issue is fixed in version 26.7.1.