
💰 Crypto Pay Python client vulnerable to DoS CVE-2026-70646 affects aiosend <3.0.7. Webhook requests are fully deserialized before HMAC verification, letting unauthenticated attackers force expensive JSON parsing and consume CPU/memory. ✅ Fixed: 3.0.7 🔎 Source: Tenable / GitHub Advisory #Python #DoS #AppSec #CyberSecurity
Post summary
CVE‑2026‑70646 is a DoS vulnerability in Crypto Pay Python client due to unauthenticated JSON deserialization; it is fixed in version 3.0.7.
