PT-2026-2925 · Unknown · Blacksheep

Tr4Ce-Ju

·

Publicado

2026-01-14

·

Atualizado

2026-01-15

·

CVE-2026-22779

CVSS v4.0

6.3

Média

VetorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions BlackSheep versions prior to 2.4.6
Description BlackSheep, an asynchronous web framework for building event-based web applications with Python, has an issue in its HTTP Client implementation. Missing validation of headers allows an attacker to modify HTTP requests, potentially inserting new headers or creating entirely new requests. Exploitation requires passing unsanitized user input directly into headers. The server component is not affected as BlackSheep relies on an underlying ASGI server for handling response headers. The attack vector involves applications using user input in HTTP client requests related to the method, URL, or headers.
Recommendations Upgrade to version 2.4.6. If handling headers from untrusted sources, reject values for header names and values that contain carriage returns.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-22779
GHSA-6PW3-H7XF-X4GP

Produtos afetados

Blacksheep