Description
Sanic is an opensource python web server/framework. In version 25.12.0, Sanic's core HTTP/1.1 chunked-body handling does not fully consume the trailer-part after the terminating zero chunk before reusing the keep-alive connection buffer. A remote unauthenticated client can place attacker-controlled bytes in that trailer region, causing Sanic to parse and route them as a hidden second request after the outer request. This breaks HTTP request-boundary integrity and can provide a request-smuggling primitive when Sanic is deployed behind intermediaries. This issue is fixed in version 25.12.1.
Published: 2026-09-17
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Request Smuggling
Action: Immediate Patch
AI Analysis

Impact

Sanic’s HTTP/1.1 chunked-body handling omits fully consuming the trailer part after the terminating zero chunk before reusing the buffer. A remote unauthenticated client can inject attacker‑controlled bytes into that trailer region, causing the framework to parse and route a hidden second request after the outer request. This breaks HTTP request‑boundary integrity and offers a request‑smuggling primitive when deployed behind intermediaries.

Affected Systems

The vulnerability affects Sanic version 25.12.0. The issue is fixed in 25.12.1 and later releases.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. A remote attacker can exploit the flaw by sending a crafted chunked request over TCP. The attacker does not need authentication, and the execution condition is that the request is routed through a Sanic instance that reuses the keep‑alive buffer. Because the vulnerability leverages a request smuggling technique, it may allow an attacker to bypass upstream filtering, inject unintended traffic, or potentially trigger further server‑side logic depending on the application code.

Generated by OpenCVE AI on September 17, 2026 at 21:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Sanic framework to version 25.12.1 or newer, which contains the fixed chunked‑body handling.
  • Configure the web server or CDN to reject or log requests containing unexpected bytes in the trailer part of a chunked transfer, effectively blocking potential smuggling attempts.
  • If immediate network changes are not feasible, disable HTTP keep‑alive or enforce per‑request connection close so that buffer reuse does not allow hidden requests to be parsed.

Generated by OpenCVE AI on September 17, 2026 at 21:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-wmj6-g64g-j7q5 sanic chunked trailer request smuggling allows hidden second request execution
History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Sanic-org
Sanic-org sanic
Vendors & Products Sanic-org
Sanic-org sanic

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Sanic is an opensource python web server/framework. In version 25.12.0, Sanic's core HTTP/1.1 chunked-body handling does not fully consume the trailer-part after the terminating zero chunk before reusing the keep-alive connection buffer. A remote unauthenticated client can place attacker-controlled bytes in that trailer region, causing Sanic to parse and route them as a hidden second request after the outer request. This breaks HTTP request-boundary integrity and can provide a request-smuggling primitive when Sanic is deployed behind intermediaries. This issue is fixed in version 25.12.1.
Title sanic chunked trailer request smuggling allows hidden second request execution
Weaknesses CWE-444
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T19:19:53.849Z

Reserved: 2026-09-02T21:21:01.776Z

Link: CVE-2026-85078

cve-icon Vulnrichment

Updated: 2026-09-17T17:06:17.345Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T15:16:55.153

Modified: 2026-09-30T17:31:44.573

Link: CVE-2026-85078

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-17T14:28:37Z

Links: CVE-2026-85078 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:02:11Z

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')