{"record":{"id":"322bf17f6f7fb538","repo":"aio-libs/aiohttp","slug":"1009-322bf1","errorCode":"1009","errorMessage":"Compressed message has too many deflate members","messagePattern":"Compressed message has too many deflate members","errorType":"exception","errorClass":"WebSocketError","httpStatus":null,"severity":"error","filePath":"aiohttp/_websocket/reader_py.py","lineNumber":261,"sourceCode":"            if compressed:\n                if not self._decompressobj:\n                    self._decompressobj = ZLibDecompressor(suppress_deflate_header=True)\n                # XXX: It's possible that the zlib backend (isal is known to\n                # do this, maybe others too?) will return max_length bytes,\n                # but internally buffer more data such that the payload is\n                # >max_length, so we return one extra byte and if we're able\n                # to do that, then the message is too big.\n                try:\n                    payload_merged = self._decompressobj.decompress_sync(\n                        assembled_payload + WS_DEFLATE_TRAILING,\n                        (\n                            self._max_msg_size + 1\n                            if self._max_msg_size\n                            else self._max_msg_size\n                        ),\n                    )\n                except TooManyMembersError as exc:\n                    raise WebSocketError(\n                        WSCloseCode.MESSAGE_TOO_BIG,\n                        \"Compressed message has too many deflate members\",\n                    ) from exc\n                if self._max_msg_size and len(payload_merged) > self._max_msg_size:\n                    raise WebSocketError(\n                        WSCloseCode.MESSAGE_TOO_BIG,\n                        f\"Decompressed message exceeds size limit {self._max_msg_size}\",\n                    )\n            elif type(assembled_payload) is bytes:\n                payload_merged = assembled_payload\n            else:\n                payload_merged = bytes(assembled_payload)\n\n            size = len(payload_merged)\n            if opcode == OP_CODE_TEXT:\n                if self._decode_text:\n                    try:\n                        text = payload_merged.decode(\"utf-8\")","sourceCodeStart":243,"sourceCodeEnd":279,"githubUrl":"https://github.com/aio-libs/aiohttp/blob/d041d4d0fd48c3f0832084d33be16cf1c4835f85/aiohttp/_websocket/reader_py.py#L243-L279","documentation":"Raised as WebSocketError code 1009 (MESSAGE_TOO_BIG) when permessage-deflate (RFC 7692) decompression of an assembled compressed message raises TooManyMembersError from the zlib decompressor. aiohttp's ZLibDecompressor caps the number of deflate members it will emit as a decompression-bomb / zip-bomb defense; exceeding that cap is treated as an oversized message even though the raw compressed bytes were small.","triggerScenarios":"self._decompressobj.decompress_sync(assembled_payload + WS_DEFLATE_TRAILING, ...) throws TooManyMembersError. This occurs when a compressed WebSocket message expands into many zlib members — a classic zip-bomb pattern where a tiny compressed payload yields a huge or pathological decompressed stream.","commonSituations":"A malicious peer sends a crafted deflate zip-bomb; a legitimate but poorly compressed stream with many flush points; interop with a compressor library that emits many small members; enabling permessage-deflate (compress=15) against untrusted clients without size limits.","solutions":["Keep permessage-deflate disabled for untrusted peers, or negotiate a smaller/no-context-takeover window.","Set a max_msg_size on the WebSocket reader so oversized decompressed messages are bounded.","Rate-limit / authenticate peers before accepting compressed frames.","If the payload is legitimately large, switch to an uncompressed BINARY channel and chunk at the application layer."],"exampleFix":"// before: deflate enabled with no bound, server accepts untrusted clients\napp['ws'] = web.WebSocketResponse(compress=15)\n// after: disable compression for untrusted peers or cap message size\napp['ws'] = web.WebSocketResponse(compress=0, max_msg_size=1*1024*1024)","handlingStrategy":"validation","validationCode":"// Cap message size and prefer no compression for untrusted peers.\nws = web.WebSocketResponse(compress=0, max_msg_size=4*1024*1024)\n# or, when compression is required, enforce a strict limit:\nws = web.WebSocketResponse(compress=15, max_msg_size=1*1024*1024)\n","typeGuard":"null","tryCatchPattern":"try:\n    msg = await ws.receive()\nexcept WebSocketError as exc:\n    if exc.code == WSCloseCode.MESSAGE_TOO_BIG:\n        log.security('possible deflate zip-bomb from %s', peer)\n    await ws.close(code=exc.code)\n","preventionTips":["Disable permessage-deflate for untrusted/unauthenticated peers.","Always set max_msg_size when compression is enabled.","Treat repeated MESSAGE_TOO_BIG from one peer as abuse and rate-limit/disconnect."],"tags":["websocket","permessage-deflate","security","zip-bomb","message-too-big","rfc7692"],"backgroundTag":null,"analyzedSha":"d041d4d0fd48c3f0832084d33be16cf1c4835f85","analyzedAt":"2026-08-11T20:44:15.550Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}