{"id":"CVE-2026-85078","summary":"sanic chunked trailer request smuggling allows hidden second request execution","details":"Sanic is an opensource python web server/framework. In version 25.12.0, Sanic's core HTTP/1.1 chunked-body handling does not fully consume the trailer-part after the terminating zero chunk before reusing the keep-alive connection buffer. A remote unauthenticated client can place attacker-controlled bytes in that trailer region, causing Sanic to parse and route them as a hidden second request after the outer request. This breaks HTTP request-boundary integrity and can provide a request-smuggling primitive when Sanic is deployed behind intermediaries. This issue is fixed in version 25.12.1.","aliases":["GHSA-wmj6-g64g-j7q5"],"modified":"2026-09-19T03:46:17.099554472Z","published":"2026-09-17T14:28:37.286Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-444"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85078.json"},"references":[{"type":"WEB","url":"https://github.com/sanic-org/sanic/releases/tag/v24.12.1"},{"type":"WEB","url":"https://github.com/sanic-org/sanic/releases/tag/v25.12.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85078.json"},{"type":"ADVISORY","url":"https://github.com/sanic-org/sanic/security/advisories/GHSA-wmj6-g64g-j7q5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85078"},{"type":"FIX","url":"https://github.com/sanic-org/sanic/commit/47349d689d65fa1907977ac100e867894aeafb22"},{"type":"FIX","url":"https://github.com/sanic-org/sanic/commit/69a10d3b06babaa9e5f6d1af577364e9e53b6dea"},{"type":"FIX","url":"https://github.com/sanic-org/sanic/commit/a332796506c7c588b6930b02a8886e43eb8ea8d6"},{"type":"FIX","url":"https://github.com/sanic-org/sanic/pull/3164"},{"type":"FIX","url":"https://github.com/sanic-org/sanic/pull/3165"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sanic-org/sanic","events":[{"introduced":"0"},{"introduced":"785d77f8fe208576a48d339bd81d866021154092"},{"fixed":"47349d689d65fa1907977ac100e867894aeafb22"},{"fixed":"ef9240ce844472745fa213de216a37e188431fa6"},{"fixed":"69a10d3b06babaa9e5f6d1af577364e9e53b6dea"},{"fixed":"a332796506c7c588b6930b02a8886e43eb8ea8d6"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"24.12.1"},{"introduced":"25.12.0"},{"fixed":"25.12.1"}]}}],"versions":["v25.3.0","v24.12.0","v23.6.0","v22.12.0","v23.3.0","v22.9.1","v22.9.0","v22.6.0","v22.3.1","v22.3.0","v21.12.0","v21.9.1","v21.9.0","v21.6.0","v21.3.2","v21.3.1","v21.3.0","v20.12.0","v20.9.1","v20.9.0","v20.6.3","v20.3.0","v19.12.1","v19.9.0","v19.6.3","v19.6.2","v19.6.1","v19.6.0","19.03.1","19.3","18.12.0","0.8.3","0.8.2","0.8.1","0.8.0","0.7.0","0.6.0","0.5.4","0.5.3","0.5.2","0.5.1","0.5.0","0.4.1","0.4.0","0.3.1","0.3.0","0.2.0","0.1.9","0.1.8","0.1.7","0.1.6","0.1.5","0.1.4","0.1.3","0.1.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85078.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"}]}