High severity8.3NVD Advisory· Published Aug 1, 2022· Updated Jun 17, 2026
CVE-2022-35920
CVE-2022-35920
Description
Sanic is an opensource python web server/framework. Affected versions of sanic allow access to lateral directories when using app.static if using encoded %2F URLs. Parent directory traversal is not impacted. Users are advised to upgrade. There is no known workaround for this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
sanicPyPI | >= 22.0.0, < 22.6.1 | 22.6.1 |
sanicPyPI | >= 21.0.0, < 21.12.2 | 21.12.2 |
sanicPyPI | < 20.12.7 | 20.12.7 |
Affected products
2Patches
Vulnerability mechanics
References
5- github.com/sanic-org/sanic/pull/2495nvdPatchThird Party AdvisoryWEB
- github.com/sanic-org/sanic/issues/2478nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-8cw9-5hmv-77w6ghsaADVISORY
- github.com/sanic-org/sanic/security/advisories/GHSA-8cw9-5hmv-77w6nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-35920ghsaADVISORY
News mentions
0No linked articles in our index yet.