
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22779 is a CRLF injection vulnerability in the HTTP Client (ClientSession) implementation of BlackSheep, an asynchronous Python web framework developed by Neoteroi. Due to missing header validation, an attacker can inject carriage return (\r) and line feed (\n) characters into HTTP request headers, the request method, or the URL, enabling HTTP request splitting or header injection. All BlackSheep versions prior to 2.4.6 are affected; the server-side component is not impacted. The vulnerability was disclosed on January 14, 2026, and carries a CVSS v3.1 score of 5.3 (Medium) and a CVSS v4.0 score of 6.3 (Medium) (GitHub Advisory, Feedly).
The root cause is classified as CWE-113 (Improper Neutralization of CRLF Sequences in HTTP Headers / HTTP Request Splitting). The write_header() function in blacksheep/scribe.py and its Cython counterpart (scribe.pyx) concatenated header names and values directly into raw HTTP bytes without stripping \r or \n characters, and the write_request_method() function similarly lacked validation of the HTTP method token. Exploitation requires a developer to pass unsanitized, attacker-controlled input into HTTP client request headers, the method field, or the URL — for example, a header value containing \nInjected-Header: malicious would result in an additional header being written into the outgoing request. The fix introduced a _nocrlf() sanitization helper that strips CR and LF bytes from header names, values, URL paths, and query strings, and added a regex check to reject invalid HTTP method tokens (GitHub Advisory, Patch Commit).
Successful exploitation allows an attacker to inject arbitrary HTTP headers into outbound requests made by the BlackSheep HTTP client, or to forge entirely new HTTP requests (HTTP request splitting). This primarily affects integrity — an attacker could manipulate backend service requests, bypass security controls, poison caches, or perform server-side request forgery-like attacks against internal services. Confidentiality and availability are not directly impacted, but header injection can facilitate session hijacking or credential theft in downstream systems if the injected headers are processed by a vulnerable backend (GitHub Advisory, Feedly).
No public exploit code or in-the-wild exploitation has been reported for CVE-2026-22779. The EPSS score is approximately 0.045%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is conditional — it requires that a developer passes unsanitized user-controlled input directly into BlackSheep HTTP client headers, limiting the attack surface to applications with this specific coding pattern (GitHub Advisory, Feedly).
ClientSession.legitimate-value\r\nX-Injected-Header: malicious-content, intended to be placed in a header value, the HTTP method, or the URL.ClientSession request (e.g., as a header value in client.get(url, headers={"X-Custom": user_input})).X-Injected-Header: malicious-content) as a separate header line, potentially manipulating the behavior of the downstream server.Users should upgrade BlackSheep to version 2.4.6 or later, which introduces CRLF sanitization via the _nocrlf() helper applied to all header names, values, URL paths, query strings, and HTTP method tokens (Release Notes, Patch Commit). As a workaround for applications that cannot immediately upgrade, developers should manually reject or sanitize any header names or values containing \r or \n characters before passing them to the BlackSheep HTTP client (GitHub Advisory).
The vulnerability was reported by security researcher Jinho Ju (@tr4ce-ju) and disclosed via GitHub's security advisory process by BlackSheep maintainer RobertoPrevato on January 14, 2026. The fix was acknowledged positively by the community, with three GitHub users reacting with a thumbs-up on the v2.4.6 release. No significant broader media coverage or notable public researcher commentary beyond the advisory itself has been identified (Release Notes, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."