← العودة للجدول
CVE-2026-44546
CVE-2026-44546 — GHSA: daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to...
📅 2026-06-03
🟢 Low 🔥 No GHSA Exploit Vulnerability CVSS 3.7

📋 الوصف الكامل

daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket handshake processing. Twisted does not treat \x0b, \x0c, \x1c, \x1d, \x1e, or \x85 as header line separators, but autobahn decodes header values to str and calls splitlines(). An attacker can exploit this parser differential to inject additional headers into the ASGI scope

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-44546

📡 المصدر

GHSA

✅ الحلول والتخفيف

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←