HTTP Request Smuggling Affecting sanic package, versions [,24.12.1)[25.3.0,25.12.1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.51% (41st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-SANIC-20046661
  • published22 Sept 2026
  • disclosed17 Sept 2026
  • creditlalala5678

Introduced: 17 Sep 2026

NewCVE-2026-85078  (opens in a new tab)
CWE-444  (opens in a new tab)

How to fix?

Upgrade sanic to version 24.12.1, 25.12.1 or higher.

Overview

Affected versions of this package are vulnerable to HTTP Request Smuggling in the HTTP/1.1 request parsing process. An attacker can cause the server to interpret leftover bytes in the connection buffer as a new, unintended HTTP request by sending specially crafted chunked requests with malicious content in the trailer area. This can result in the backend executing unauthorized requests within the same connection, potentially bypassing intended request boundaries and leading to unauthorized actions.

CVSS Base Scores

version 4.0
version 3.1