HTTP Response Splitting Affecting blacksheep package, versions [2.3.1a1, 2.4.6)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.32% (25th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-BLACKSHEEP-14943967
  • published15 Jan 2026
  • disclosed14 Jan 2026
  • creditJinho Ju

Introduced: 14 Jan 2026

CVE-2026-22779  (opens in a new tab)
CWE-113  (opens in a new tab)
CWE-93  (opens in a new tab)

How to fix?

Upgrade blacksheep to version 2.4.6 or higher.

Overview

blacksheep is a Fast web framework for Python asyncio

Affected versions of this package are vulnerable to HTTP Response Splitting via the Client implementation. An attacker can manipulate HTTP requests or inject additional headers by supplying specially input containing carriage return and line feed characters in HTTP client headers.

CVSS Base Scores

version 4.0
version 3.1