THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-wmj6-g64g-j7q5 (medium) — sanic chunked trailer request smuggling allows hidden second request execution

[GHSA] GHSA-wmj6-g64g-j7q5 (medium) — sanic chunked trailer request smuggling allows hidden second request execution

highgithub_advisoriesPublished 2026-09-17

GHSA-wmj6-g64g-j7q5 Severity: medium CVE: CVE-2026-85078

sanic chunked trailer request smuggling allows hidden second request execution

## Description

Sanic's HTTP/1.1 chunked-body handling does not fully consume the `trailer-part` after the terminating `0\r\n` chunk. Because of that, attacker-controlled bytes left in the connection buffer after the first chunked request can be interpreted as t

Indicators of compromise

Original source: https://github.com/advisories/GHSA-wmj6-g64g-j7q5