VYPR

PyPI package

aiosend

pkg:pypi/aiosend

Vulnerabilities (1)

  • CVE-2026-70646HigAug 6, 2026
    affected < 3.0.7fixed 3.0.7

    aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMAC signature. This allows an unauthenticated attacker to force expensive parsing of arbitrary JSON pa