Description
Sanic is an opensource python web server/framework. Prior to version 24.12.1, and in version 25.12.0, the HTTP/1.1 response pipeline in sanic/response/types.py serializes response header names and values without rejecting carriage-return or line-feed characters. Applications that place attacker-controlled data in response.headers, file(..., filename=...), or cookie path and domain attributes can therefore emit injected headers and may split responses. Depending on application and proxy behavior, this can enable session fixation through injected cookies, cache poisoning, or security-header corruption. This issue is fixed in versions 24.12.1 and 25.12.1.
Published: 2026-09-17
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: HTTP Header Injection leading to session fixation, cache poisoning, or security header corruption
Action: Patch Now
AI Analysis

Impact

The vulnerability allows the Sanic framework to emit HTTP response headers that contain attacker‑controlled carriage‑return or line‑feed characters because these characters are not validated when serializing header names and values. This flaw, identified as CWE‑113, enables an attacker to inject arbitrary headers, split the response, and insert malicious cookie definitions, potentially causing session fixation, cache poisoning, or corruption of essential security headers.

Affected Systems

Deployments of the Sanic Python web framework older than version 24.12.1 and the 25.12.0 release are affected. The issue is fixed in releases 24.12.1 and 25.12.1 and in all later versions. Any installation using an older release should be examined for usage of response.headers, file(..., filename=...), or cookie path and domain attributes that might contain untrusted data.

Risk and Exploitability

The severity of the flaw is reflected in a CVSS score of 8.2, indicating high potential impact. An EPSS score is not available, so the current exploitation probability is uncertain, and the vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires an attacker to influence the generation of HTTP response headers—such as by supplying request values that the application incorporates into response.headers or cookie attributes—and then triggering the vulnerable response, which can result in session fixation, cache poisoning, or header spoofing.

Generated by OpenCVE AI on September 17, 2026 at 21:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Sanic to version 24.12.1 or newer, including the 25.12.1 release, to receive the fixed header validation logic.
  • Identify any application code that writes to response.headers, uses the filename argument of file(), or sets cookie path or domain attributes, and refactor it to avoid using untrusted data.
  • Implement input validation in the application that rejects carriage‑return and line‑feed characters in header names and values before they reach the Sanic response pipeline, as a temporary mitigation if a patch cannot be applied immediately.

Generated by OpenCVE AI on September 17, 2026 at 21:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-93
References
Metrics threat_severity

None

threat_severity

Important


Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Sanic-org
Sanic-org sanic
Vendors & Products Sanic-org
Sanic-org sanic

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Sanic is an opensource python web server/framework. Prior to version 24.12.1, and in version 25.12.0, the HTTP/1.1 response pipeline in sanic/response/types.py serializes response header names and values without rejecting carriage-return or line-feed characters. Applications that place attacker-controlled data in response.headers, file(..., filename=...), or cookie path and domain attributes can therefore emit injected headers and may split responses. Depending on application and proxy behavior, this can enable session fixation through injected cookies, cache poisoning, or security-header corruption. This issue is fixed in versions 24.12.1 and 25.12.1.
Title Sanic: HTTP response header injection via missing CR/LF validation in Sanic HTTP/1.1 responses
Weaknesses CWE-113
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T20:45:15.589Z

Reserved: 2026-09-02T21:21:01.776Z

Link: CVE-2026-85077

cve-icon Vulnrichment

Updated: 2026-09-21T20:45:09.003Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T15:16:54.990

Modified: 2026-09-24T21:22:19.873

Link: CVE-2026-85077

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-17T14:26:39Z

Links: CVE-2026-85077 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:30:18Z

Weaknesses
  • CWE-113

    Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')

  • CWE-93

    Improper Neutralization of CRLF Sequences ('CRLF Injection')