HTTP Response Splitting Affecting gakido package, versions [,0.1.1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.36% (28th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-GAKIDO-15124005
  • published28 Jan 2026
  • disclosed26 Jan 2026
  • creditOmar Kurt

Introduced: 26 Jan 2026

CVE-2026-24489  (opens in a new tab)
CWE-113  (opens in a new tab)
CWE-93  (opens in a new tab)

How to fix?

Upgrade gakido to version 0.1.1 or higher.

Overview

gakido is a High-performance CPython HTTP client with browser impersonation.

Affected versions of this package are vulnerable to HTTP Response Splitting via improper sanitization of user-supplied header values and names in the canonicalize_headers function. An attacker can inject arbitrary HTTP headers, manipulate HTTP responses, poison caches, fix sessions, or bypass security controls by supplying specially crafted input containing CRLF or null byte characters.

CVSS Base Scores

version 4.0
version 3.1