« Volver al listado

CVE-2026-44546

Estado: AnalizadaMedia (5.3)—

daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket handshake processing. Twisted does not treat \x0b, \x0c, \x1c, \x1d, \x1e, or \x85 as header line separators, but autobahn decodes header values to str and calls splitlines(). An attacker can exploit this parser differential to inject additional headers into the ASGI scope passed to the application. daphne now rejects requests with these bytes in any header value with a 400 response.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-44546",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-44546",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-03T15:45:59.459546Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "6a34fbeb-21d4-45e7-8e0a-62b95bc12c92",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.7,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "6a34fbeb-21d4-45e7-8e0a-62b95bc12c92",
      "affectedData": [
        {
          "repo": "https://github.com/django/daphne/",
          "vendor": "djangoproject",
          "product": "daphne",
          "versions": [
            {
              "status": "affected",
              "version": "4.2.0",
              "versionType": "python",
              "lessThanOrEqual": "4.2.1"
            },
            {
              "status": "unaffected",
              "version": "4.2.2",
              "versionType": "python"
            }
          ],
          "packageName": "daphne",
          "collectionURL": "https://pypi.org/project/daphne/",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-06-03T14:16:43.720",
  "references": [
    {
      "url": "https://github.com/django/daphne/blob/main/CHANGELOG.txt",
      "tags": [
        "Release Notes"
      ],
      "source": "6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "6a34fbeb-21d4-45e7-8e0a-62b95bc12c92",
      "description": [
        {
          "lang": "en",
          "value": "CWE-444"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket handshake processing. Twisted does not treat \\x0b, \\x0c, \\x1c, \\x1d, \\x1e, or \\x85 as header line separators, but autobahn decodes header values to str and calls splitlines(). An attacker can exploit this parser differential to inject additional headers into the ASGI scope passed to the application. daphne now rejects requests with these bytes in any header value with a 400 response."
    },
    {
      "lang": "es",
      "value": "daphne anterior a la versión 4.2.2 reconstruye una solicitud HTTP en bruto a partir de los encabezados analizados de Twisted y la alimenta a autobahn para el procesamiento del handshake de WebSocket. Twisted no trata \\x0b, \\x0c, \\x1c, \\x1d, \\x1e, o \\x85 como separadores de línea de encabezado, pero autobahn decodifica los valores de los encabezados a str y llama a splitlines(). Un atacante puede explotar este diferencial del analizador para inyectar encabezados adicionales en el ámbito ASGI pasado a la aplicación. daphne ahora rechaza las solicitudes con estos bytes en cualquier valor de encabezado con una respuesta 400."
    }
  ],
  "lastModified": "2026-07-22T19:10:00.120",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:djangoproject:daphne:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "48E446D3-9A77-40A0-A62A-D3F04DF924AB",
              "versionEndExcluding": "4.2.2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"
}