Executive brief
A vulnerability in the aiosend library's webhook handler allows an unauthenticated attacker to cause a denial-of-service (DoS) condition. The software processes and validates large amounts of incoming data before checking if the sender is authorized, leading to excessive CPU and memory consumption. This can slow down or crash the service, preventing legitimate transactions or updates from being processed.
Technical details
The vulnerability exists in `WebhookHandler.feed_update()` within `aiosend/webhook/base.py`. The method calls `Update.model_validate()` to deserialize the incoming JSON body via Pydantic before executing `_check_signature()`. Because `CryptoPayObject` is configured with `extra="allow"`, an attacker can send large, complex JSON payloads with arbitrary fields that the server will parse and store in memory before rejecting the request due to an invalid signature. This lack of early authentication and body size limits at the library level allows for unauthenticated resource exhaustion (CPU and RAM). The issue is fixed in version 3.0.6.
Affected products
- vovchic17 aiosend < 3.0.6
Timeline
- 2026-05-16: disclosed
- 2026-05-22: advisory: GitHub Advisory published
- 3.0.6: patched
References
- https://api.github.com/users/7p9eiiwqo8kos
- https://github.com/7p9eiiwqo8kos
- https://api.github.com/users/7p9eiiwqo8kos/gists%7B/gist_id%7D
- https://api.github.com/users/7p9eiiwqo8kos/repos
- https://avatars.githubusercontent.com/u/193345660?v=4
- https://api.github.com/users/7p9eiiwqo8kos/events%7B/privacy%7D