CVE-2026-24489: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-24489 is an HTTP Header Injection (CRLF Injection) vulnerability in Gakido, a Python HTTP client focused on browser impersonation and anti-bot evasion. The vulnerability affects all versions prior to 0.1.1 (i.e., ≤ 0.1.0) and was discovered and disclosed on January 25, 2026, with the patch released the same day. It carries a CVSS v3.1 base score of 5.3 (Moderate) (Github Advisory, Feedly).

Technical details

The root cause is improper neutralization of CRLF sequences in HTTP headers (CWE-93, CWE-113), specifically within the canonicalize_headers() function in gakido/headers.py. When user-controlled header names or values containing \r\n (CRLF), \n (LF), or \x00 (null byte) characters were passed to request methods such as Client.get() or Client.post(), these characters were not stripped before being included in outgoing HTTP requests, allowing an attacker to inject arbitrary additional headers. The attack requires no authentication and is exploitable over the network with low complexity. The fix in version 0.1.1 introduces a _sanitize_header() function that strips all three character types from both header names and values before processing (Github Advisory, Patch Commit).

Impact

An attacker who can control header values passed to Gakido's request methods can inject arbitrary HTTP headers into outgoing requests, potentially enabling HTTP response splitting in proxy configurations, cache poisoning of intermediate caches, session fixation via injected Set-Cookie headers, and bypass of server-side security controls. The CVSS assessment reflects a low integrity impact with no confidentiality or availability impact, as the vulnerability primarily enables request manipulation rather than direct data exfiltration or service disruption (Github Advisory).

Exploitability

A proof-of-concept is publicly available in the GitHub Security Advisory, demonstrating injection of an X-Injected header by embedding \r\n in a User-Agent value passed to Client.get(). There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.013% (0.021% per GitHub Advisory), placing it in the 6th percentile for exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory).

Exploitation steps

  1. Identify vulnerable usage: Locate an application that uses Gakido (pip package gakido) version ≤ 0.1.0 and passes user-controlled data as HTTP header names or values to Client.get(), Client.post(), or similar methods.
  2. Craft a malicious header value: Construct a header value containing a CRLF sequence to inject an additional header, e.g., "test\r\nX-Injected: pwned" as the User-Agent value.
  3. Submit the payload: Trigger the application to make an HTTP request using the crafted header value, for example:
    from gakido import Client
    c = Client(impersonate="chrome_120")
    r = c.get("https://target.example.com/endpoint", headers={
        "User-Agent": "test\r\nX-Injected: pwned"
    })
  4. Observe injected header: The target server receives two separate headers — User-Agent: test and X-Injected: pwned — as if they were legitimately sent, enabling further attacks such as cache poisoning, session fixation, or security control bypass depending on the server and proxy configuration (Github Advisory).

Mitigation and workarounds

Upgrade Gakido to version 0.1.1 or later, which introduces the _sanitize_header() function that strips \r, \n, and \x00 characters from all header names and values before they are sent. No configuration-based workaround is available for the unpatched library; the only remediation is upgrading via pip (pip install --upgrade gakido). Applications that pass user-controlled data as header values should also independently validate and sanitize such input as a defense-in-depth measure (Github Advisory, Patch Release).

Community reactions

Coverage of this vulnerability has been limited to automated vulnerability tracking platforms and a small number of security news outlets. CyberSecurityNews and ITSecurityNews published brief articles noting that the flaw allows attackers to bypass security controls via CRLF injection (CyberSecurityNews). A technical blog post analyzing the vulnerability in gakido/headers.py was also published shortly after disclosure (CryptoBivash Blog). No significant vendor statements or notable researcher commentary beyond the original advisory have been identified.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management