
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24489 is an HTTP Header Injection (CRLF Injection) vulnerability in Gakido, a Python HTTP client focused on browser impersonation and anti-bot evasion. The vulnerability affects all versions prior to 0.1.1 (i.e., ≤ 0.1.0) and was discovered and disclosed on January 25, 2026, with the patch released the same day. It carries a CVSS v3.1 base score of 5.3 (Moderate) (Github Advisory, Feedly).
The root cause is improper neutralization of CRLF sequences in HTTP headers (CWE-93, CWE-113), specifically within the canonicalize_headers() function in gakido/headers.py. When user-controlled header names or values containing \r\n (CRLF), \n (LF), or \x00 (null byte) characters were passed to request methods such as Client.get() or Client.post(), these characters were not stripped before being included in outgoing HTTP requests, allowing an attacker to inject arbitrary additional headers. The attack requires no authentication and is exploitable over the network with low complexity. The fix in version 0.1.1 introduces a _sanitize_header() function that strips all three character types from both header names and values before processing (Github Advisory, Patch Commit).
An attacker who can control header values passed to Gakido's request methods can inject arbitrary HTTP headers into outgoing requests, potentially enabling HTTP response splitting in proxy configurations, cache poisoning of intermediate caches, session fixation via injected Set-Cookie headers, and bypass of server-side security controls. The CVSS assessment reflects a low integrity impact with no confidentiality or availability impact, as the vulnerability primarily enables request manipulation rather than direct data exfiltration or service disruption (Github Advisory).
A proof-of-concept is publicly available in the GitHub Security Advisory, demonstrating injection of an X-Injected header by embedding \r\n in a User-Agent value passed to Client.get(). There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.013% (0.021% per GitHub Advisory), placing it in the 6th percentile for exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory).
gakido) version ≤ 0.1.0 and passes user-controlled data as HTTP header names or values to Client.get(), Client.post(), or similar methods."test\r\nX-Injected: pwned" as the User-Agent value.from gakido import Client
c = Client(impersonate="chrome_120")
r = c.get("https://target.example.com/endpoint", headers={
"User-Agent": "test\r\nX-Injected: pwned"
})User-Agent: test and X-Injected: pwned — as if they were legitimately sent, enabling further attacks such as cache poisoning, session fixation, or security control bypass depending on the server and proxy configuration (Github Advisory).Upgrade Gakido to version 0.1.1 or later, which introduces the _sanitize_header() function that strips \r, \n, and \x00 characters from all header names and values before they are sent. No configuration-based workaround is available for the unpatched library; the only remediation is upgrading via pip (pip install --upgrade gakido). Applications that pass user-controlled data as header values should also independently validate and sanitize such input as a defense-in-depth measure (Github Advisory, Patch Release).
Coverage of this vulnerability has been limited to automated vulnerability tracking platforms and a small number of security news outlets. CyberSecurityNews and ITSecurityNews published brief articles noting that the flaw allows attackers to bypass security controls via CRLF injection (CyberSecurityNews). A technical blog post analyzing the vulnerability in gakido/headers.py was also published shortly after disclosure (CryptoBivash Blog). No significant vendor statements or notable researcher commentary beyond the original advisory have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."