PT-2026-94354 · Sanic · Sanic
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Sanic version 25.12.0
Description
Sanic's core HTTP/1.1 parser fails to fully consume the
trailer-part after the terminating zero chunk before reusing the keep-alive connection buffer. A remote unauthenticated client can place attacker-controlled bytes in this trailer region, which Sanic then parses and routes as a hidden second request following the initial outer request. This failure in request-boundary integrity can enable request smuggling when Sanic is deployed behind intermediaries such as reverse proxies, gateways, or caches.Recommendations
Update Sanic to version 25.12.1.
Exploit
Fix
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sanic