Uncaught Exception Affecting granian package, versions [,2.7.4)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.32% (24th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-GRANIAN-16635313
  • published11 May 2026
  • disclosed6 May 2026
  • creditReporter

Introduced: 6 May 2026

CVE-2026-42544  (opens in a new tab)
CWE-248  (opens in a new tab)

How to fix?

Upgrade granian to version 2.7.4 or higher.

Overview

granian is an A Rust HTTP server for Python applications

Affected versions of this package are vulnerable to Uncaught Exception via the Sec-WebSocket-Protocol header processing in the WebSocket upgrade request path. An attacker can cause a worker process to terminate unexpectedly by sending a specially crafted WebSocket upgrade request containing non-ASCII bytes in the Sec-WebSocket-Protocol header. This can be repeated across multiple workers to take the service offline. This is only exploitable if the server is running with the default panic behavior that aborts the worker process.

CVSS Base Scores

version 4.0
version 3.1