Impact
Sanic’s HTTP/1.1 chunked-body handling omits fully consuming the trailer part after the terminating zero chunk before reusing the buffer. A remote unauthenticated client can inject attacker‑controlled bytes into that trailer region, causing the framework to parse and route a hidden second request after the outer request. This breaks HTTP request‑boundary integrity and offers a request‑smuggling primitive when deployed behind intermediaries.
Affected Systems
The vulnerability affects Sanic version 25.12.0. The issue is fixed in 25.12.1 and later releases.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. A remote attacker can exploit the flaw by sending a crafted chunked request over TCP. The attacker does not need authentication, and the execution condition is that the request is routed through a Sanic instance that reuses the keep‑alive buffer. Because the vulnerability leverages a request smuggling technique, it may allow an attacker to bypass upstream filtering, inject unintended traffic, or potentially trigger further server‑side logic depending on the application code.
OpenCVE Enrichment
Github GHSA