CVE-2026-22779: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-22779 is a CRLF injection vulnerability in the HTTP Client (ClientSession) implementation of BlackSheep, an asynchronous Python web framework developed by Neoteroi. Due to missing header validation, an attacker can inject carriage return (\r) and line feed (\n) characters into HTTP request headers, the request method, or the URL, enabling HTTP request splitting or header injection. All BlackSheep versions prior to 2.4.6 are affected; the server-side component is not impacted. The vulnerability was disclosed on January 14, 2026, and carries a CVSS v3.1 score of 5.3 (Medium) and a CVSS v4.0 score of 6.3 (Medium) (GitHub Advisory, Feedly).

Technical details

The root cause is classified as CWE-113 (Improper Neutralization of CRLF Sequences in HTTP Headers / HTTP Request Splitting). The write_header() function in blacksheep/scribe.py and its Cython counterpart (scribe.pyx) concatenated header names and values directly into raw HTTP bytes without stripping \r or \n characters, and the write_request_method() function similarly lacked validation of the HTTP method token. Exploitation requires a developer to pass unsanitized, attacker-controlled input into HTTP client request headers, the method field, or the URL — for example, a header value containing \nInjected-Header: malicious would result in an additional header being written into the outgoing request. The fix introduced a _nocrlf() sanitization helper that strips CR and LF bytes from header names, values, URL paths, and query strings, and added a regex check to reject invalid HTTP method tokens (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows an attacker to inject arbitrary HTTP headers into outbound requests made by the BlackSheep HTTP client, or to forge entirely new HTTP requests (HTTP request splitting). This primarily affects integrity — an attacker could manipulate backend service requests, bypass security controls, poison caches, or perform server-side request forgery-like attacks against internal services. Confidentiality and availability are not directly impacted, but header injection can facilitate session hijacking or credential theft in downstream systems if the injected headers are processed by a vulnerable backend (GitHub Advisory, Feedly).

Exploitability

No public exploit code or in-the-wild exploitation has been reported for CVE-2026-22779. The EPSS score is approximately 0.045%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is conditional — it requires that a developer passes unsanitized user-controlled input directly into BlackSheep HTTP client headers, limiting the attack surface to applications with this specific coding pattern (GitHub Advisory, Feedly).

Exploitation steps

  1. Identify a vulnerable application: Find a Python application using BlackSheep versions prior to 2.4.6 that passes user-controlled input (e.g., from query parameters, form fields, or API inputs) directly into HTTP client request headers via ClientSession.
  2. Craft a CRLF payload: Construct a malicious input string containing CRLF sequences, such as legitimate-value\r\nX-Injected-Header: malicious-content, intended to be placed in a header value, the HTTP method, or the URL.
  3. Trigger the vulnerable code path: Submit the crafted input through the application's interface so it is passed unsanitized to a BlackSheep ClientSession request (e.g., as a header value in client.get(url, headers={"X-Custom": user_input})).
  4. Observe header injection: The outbound HTTP request will contain the injected header (X-Injected-Header: malicious-content) as a separate header line, potentially manipulating the behavior of the downstream server.
  5. Escalate if possible: Depending on the downstream service, leverage the injected headers to bypass authentication, poison caches, or forge requests to internal APIs (GitHub Advisory, Patch Commit).

Indicators of compromise

  • Network: Outbound HTTP requests from a BlackSheep application containing unexpected or duplicate headers not set by application logic; requests with unusual HTTP method strings containing encoded CRLF sequences.
  • Logs: Application or proxy logs showing HTTP requests with malformed or injected headers (e.g., headers with embedded newlines or unexpected header names); downstream service logs recording headers not originating from the application's code.
  • Application Behavior: Unexpected responses from downstream APIs or services that suggest header manipulation; cache poisoning symptoms such as incorrect cached responses being served to users.

Mitigation and workarounds

Users should upgrade BlackSheep to version 2.4.6 or later, which introduces CRLF sanitization via the _nocrlf() helper applied to all header names, values, URL paths, query strings, and HTTP method tokens (Release Notes, Patch Commit). As a workaround for applications that cannot immediately upgrade, developers should manually reject or sanitize any header names or values containing \r or \n characters before passing them to the BlackSheep HTTP client (GitHub Advisory).

Community reactions

The vulnerability was reported by security researcher Jinho Ju (@tr4ce-ju) and disclosed via GitHub's security advisory process by BlackSheep maintainer RobertoPrevato on January 14, 2026. The fix was acknowledged positively by the community, with three GitHub users reacting with a thumbs-up on the v2.4.6 release. No significant broader media coverage or notable public researcher commentary beyond the advisory itself has been identified (Release Notes, GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management