Impact
The vulnerability allows the Sanic framework to emit HTTP response headers that contain attacker‑controlled carriage‑return or line‑feed characters because these characters are not validated when serializing header names and values. This flaw, identified as CWE‑113, enables an attacker to inject arbitrary headers, split the response, and insert malicious cookie definitions, potentially causing session fixation, cache poisoning, or corruption of essential security headers.
Affected Systems
Deployments of the Sanic Python web framework older than version 24.12.1 and the 25.12.0 release are affected. The issue is fixed in releases 24.12.1 and 25.12.1 and in all later versions. Any installation using an older release should be examined for usage of response.headers, file(..., filename=...), or cookie path and domain attributes that might contain untrusted data.
Risk and Exploitability
The severity of the flaw is reflected in a CVSS score of 8.2, indicating high potential impact. An EPSS score is not available, so the current exploitation probability is uncertain, and the vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires an attacker to influence the generation of HTTP response headers—such as by supplying request values that the application incorporates into response.headers or cookie attributes—and then triggering the vulnerable response, which can result in session fixation, cache poisoning, or header spoofing.
OpenCVE Enrichment