<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T15:38:07.337972+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-24489</id>
    <title>CVE-2026-24489 — Gakido vulnerable to HTTP Header Injection (CRLF Injection)</title>
    <updated>2026-10-06T15:38:07.368825+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> HappyHackingSpace gakido</p>
<p>Gakido is a Python HTTP client focused on browser impersonation and anti-bot evasion. A vulnerability was discovered in Gakido prior to version 0.1.1 that allowed HTTP header injection through CRLF (Carriage Return Line Feed) sequences in user-supplied header values and names. When making HTTP requests with user-controlled header values containing `\r\n` (CRLF), `\n` (LF), or `\x00` (null byte) characters, an attacker could inject arbitrary HTTP headers into the request. The fix in version 0.1.1 adds a `_sanitize_header()` function that strips `\r`, `\n`, and `\x00` characters from both header names and values before they are included in HTTP requests.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-24489"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gcgx-chcp-hxp9</id>
    <title>GHSA-gcgx-chcp-hxp9 — Gakido vulnerable to HTTP Header Injection (CRLF Injection)</title>
    <updated>2026-10-06T15:38:07.368887+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: gakido</p>
<p>A vulnerability was discovered in Gakido that allowed HTTP Header Injection through CRLF (Carriage Return Line Feed) sequences in user-supplied header values and names.</p>
<p>When making HTTP requests with user-controlled header values containing `\r\n` (CRLF), `\n` (LF), or `\x00` (null byte) characters, an attacker could inject arbitrary HTTP headers into the request.</p>
<p>## Impact</p>
<p>An attacker who can control header values passed to Gakido's `Client.get()`, `Client.post()`, or other request methods could:</p>
<p>1. **Inject arbitrary HTTP headers** - Add malicious headers to requests
2. **HTTP Response Splitting** - Potentially manipulate responses in certain proxy configurations
3. **Cache Poisoning** - Inject headers that could poison intermediate caches
4. **Session Fixation** - Inject session-related headers
5. **Bypass Security Controls** - Inject headers that bypass server-side security checks</p>
<p>## Proof of Concept</p>
<p>```python
from gakido import Client</p>
<p># Before fix: X-Injected header would be sent as a separate header
c = Client(impersonate="chrome_120")
r = c.get("https://httpbin.org/headers", headers={
    "User-Agent": "test\r\nX-Injected: pwned"
})</p>
<p># The server would receive:
# User-Agent: test
# X-Injected: pwned
```</p>
<p>## Affected Code</p>
<p>The vulnerability existed in the header processing logic where user-supplied headers were not sanitized before being sent in HTTP requests.</p>
<p>**File:** `gakido/headers.py`  
**Function:** `canonicalize_headers()`</p>
<p>## Fix</p>
<p>The fix adds a `_sanit…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gcgx-chcp-hxp9"/>
  </entry>
</feed>
