VYPR
Vendor

Sanic Project

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2017-16762HigNov 10, 2017
    risk 0.49cvss 7.5epss 0.02

    Sanic before 0.5.1 allows reading arbitrary files with directory traversal, as demonstrated by the /static/..%2f substring.

  • CVE-2022-35920HigAug 1, 2022
    risk 0.47cvss 8.3epss 0.01

    Sanic is an opensource python web server/framework. Affected versions of sanic allow access to lateral directories when using `app.static` if using encoded `%2F` URLs. Parent directory traversal is not impacted. Users are advised to upgrade. There is no known workaround for this…