Junglewise Threat Intelligence

CVE-2026-70646: aiosend Crypto Pay API webhook HMAC validation bypass

CVE-2026-70646 · Severity: high · CVSS 7.5 · Published 2026-08-06

Vendors: PyPI.

Executive brief

aiosend is a Python library for interacting with the Crypto Pay API. The webhook handler in versions prior to 3.0.7 validates request authenticity after parsing incoming JSON data, allowing attackers to submit large or malicious payloads that consume server resources (CPU and memory) before being rejected as inauthentic. This can lead to service degradation or denial of service against webhook endpoints.

Technical details

The vulnerability is a timing/validation-order flaw in the `WebhookHandler.feed_update()` method. The affected code deserializes the entire incoming JSON request body before verifying the HMAC signature, allowing an unauthenticated attacker to trigger expensive parsing of arbitrary payloads. The attacker can submit large, complex, or deeply nested JSON structures that consume significant CPU and memory during parsing; these payloads are ultimately discarded when HMAC verification fails. Version 3.0.7 reorders the validation logic to verify the HMAC signature before parsing, preventing resource exhaustion. Workarounds include rate-limiting webhook endpoints, enforcing request body size limits at the reverse proxy or framework level, and rejecting oversized requests before parsing.

Affected products

  • aiosend aiosend before 3.0.7

Timeline

  • 2026-08-06: disclosed
  • 2026-06-22: patched: Version 3.0.7 released

References

Related threats