CVE-2026-85078

MEDIUM Status: Received

CVSS Scores

CVSS v3.x Base Score
6.5
MEDIUM

Description

Sanic is an opensource python web server/framework. In version 25.12.0, Sanic's core HTTP/1.1 chunked-body handling does not fully consume the trailer-part after the terminating zero chunk before reusing the keep-alive connection buffer. A remote unauthenticated client can place attacker-controlled bytes in that trailer region, causing Sanic to parse and route them as a hidden second request after the outer request. This breaks HTTP request-boundary integrity and can provide a request-smuggling primitive when Sanic is deployed behind intermediaries. This issue is fixed in version 25.12.1.

Published
September 17, 2026 3:16 PM
Last Modified
September 17, 2026 3:16 PM
Source
[email protected]

Weaknesses (CWE)

CWE-444

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.