Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Rene Henningsen

#47822of 53,633
5.3Total CVSS
Vulnerabilities · 1
PT-2026-45941
5.3
2026-06-03
Twisted Software Foundation · Twisted · CVE-2026-44546
**Name of the Vulnerable Software and Affected Versions** daphne versions prior to 4.2.2 **Description** A parser differential exists when reconstructing raw HTTP requests from Twisted's parsed headers for WebSocket handshake processing in autobahn. While Twisted does not recognize the bytes `x0b`, `x0c`, `x1c`, `x1d`, `x1e`, or `x85` as header line separators, autobahn decodes these values to strings and utilizes the `splitlines()` function. This discrepancy allows an attacker to inject additional headers into the ASGI scope passed to the application. **Recommendations** Update to version 4.2.2 or later.