{"record":{"id":"0c12668b30b986c1","repo":"aio-libs/aiohttp","slug":"1009","errorCode":"1009","errorMessage":"Compressed message has too many deflate members","messagePattern":"Compressed message has too many deflate members","errorType":"exception","errorClass":"WebSocketError","httpStatus":null,"severity":"error","filePath":"aiohttp/_websocket/reader_c.py","lineNumber":261,"sourceCode":"            if compressed:\n                if not self._decompressobj:\n                    self._decompressobj = ZLibDecompressor(suppress_deflate_header=True)\n                # XXX: It's possible that the zlib backend (isal is known to\n                # do this, maybe others too?) will return max_length bytes,\n                # but internally buffer more data such that the payload is\n                # >max_length, so we return one extra byte and if we're able\n                # to do that, then the message is too big.\n                try:\n                    payload_merged = self._decompressobj.decompress_sync(\n                        assembled_payload + WS_DEFLATE_TRAILING,\n                        (\n                            self._max_msg_size + 1\n                            if self._max_msg_size\n                            else self._max_msg_size\n                        ),\n                    )\n                except TooManyMembersError as exc:\n                    raise WebSocketError(\n                        WSCloseCode.MESSAGE_TOO_BIG,\n                        \"Compressed message has too many deflate members\",\n                    ) from exc\n                if self._max_msg_size and len(payload_merged) > self._max_msg_size:\n                    raise WebSocketError(\n                        WSCloseCode.MESSAGE_TOO_BIG,\n                        f\"Decompressed message exceeds size limit {self._max_msg_size}\",\n                    )\n            elif type(assembled_payload) is bytes:\n                payload_merged = assembled_payload\n            else:\n                payload_merged = bytes(assembled_payload)\n\n            size = len(payload_merged)\n            if opcode == OP_CODE_TEXT:\n                if self._decode_text:\n                    try:\n                        text = payload_merged.decode(\"utf-8\")","sourceCodeStart":243,"sourceCodeEnd":279,"githubUrl":"https://github.com/aio-libs/aiohttp/blob/d041d4d0fd48c3f0832084d33be16cf1c4835f85/aiohttp/_websocket/reader_c.py#L243-L279","documentation":"While decompressing a `permessage-deflate` message, the zlib backend raised `TooManyMembersError` — the deflate stream contains too many dictionary members / expands without bound. This is a DoS guard against zip-bomb payloads; the reader closes the connection with code 1009 (message too big).","triggerScenarios":"Peer sends a compressed WS message whose deflate stream is pathological (many members) or expands hugely; a back-end such as isal hits its internal member limit during `decompress_sync`.","commonSituations":"Malicious client sending a compression bomb; buggy encoder producing a malformed/infinite deflate stream; interop with a peer emitting many deflate blocks.","solutions":["If traffic is legitimate, tune compression: negotiate `server_no_context_takeover`/`client_no_context_takeover` to bound decoder state.","Keep/raise `max_msg_size` appropriately; otherwise treat the 1009 as desired protection and drop the connection.","Rate-limit or disconnect repeat offenders at the application layer."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"# bound decoder state and size during handshake/setup\nws = await session.ws_connect(url, compress=15, max_msg_size=4 * 1024 * 1024)","typeGuard":"def is_error(msg) -> bool:\n    return msg.type == aiohttp.WSMsgType.ERROR","tryCatchPattern":"msg = await ws.receive()\nif msg.type == aiohttp.WSMsgType.ERROR:\n    exc = msg.data            # a WebSocketError\n    close_code = exc.code     # 1002/1007/1009/...\n    log.warning(\"ws protocol error %s: %s\", close_code, exc)","preventionTips":["Prefer `*_no_context_takeover` when negotiating deflate with untrusted peers.","Treat 1009 from compressed messages as a likely zip-bomb; disconnect the peer."],"tags":["websocket","compression","security","dos","deflate","close-code-1009"],"backgroundTag":null,"analyzedSha":"d041d4d0fd48c3f0832084d33be16cf1c4835f85","analyzedAt":"2026-08-11T20:44:15.550Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}