<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 08:46:13 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-319280</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-319280</link>
      <description>EUVD-2026-319280</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-319280</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42544</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42544</link>
      <description>&lt;p&gt;Granian is a Rust HTTP server for Python applications. From 1.2.0 to 2.7.4, Granian aborts a worker process when an unauthenticated client sends a WebSocket upgrade request whose Sec-WebSocket-Protocol header contains non-ASCII bytes. The crash happens in Granian&amp;#39;s WebSocket scope construction path, before the ASGI application is invoked. This vulnerability is fixed in 2.7.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Granian is a Rust HTTP server for Python applications. From 1.2.0 to 2.7.4, Granian aborts a worker process when an unauthenticated client sends a WebSocket upgrade request whose Sec-WebSocket-Protocol header contains non-ASCII bytes. The crash happens in Granian&amp;#39;s WebSocket scope construction path, before the ASGI application is invoked. This vulnerability is fixed in 2.7.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42544</guid>
    </item>
    <item>
      <title>GHSA-vrg7-482j-p6f6 — Granian vulnerable to unauthenticated DoS via WebSocket subprotocol header panic</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vrg7-482j-p6f6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: granian&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Granian aborts a worker process when an unauthenticated client sends a WebSocket upgrade request whose `Sec-WebSocket-Protocol` header contains non-ASCII bytes.&lt;/p&gt;
&lt;p&gt;The crash happens in Granian&amp;#39;s WebSocket scope construction path, before the ASGI application is invoked.&lt;/p&gt;
&lt;p&gt;This is a single-request Denial Of Service against one worker. Repeating the request across workers takes the service offline.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;https://github.com/emmett-framework/granian/blob/bdd5b0fbbb2aca6f2f4c0d2700c244d190958035/src/asgi/utils.rs#L122-L125&lt;/p&gt;
&lt;p&gt;`HeaderValue::to_str()` returns `Err` for bytes outside visible ASCII. The subsequent `.unwrap()` panics.&lt;/p&gt;
&lt;p&gt;In release builds Granian sets `panic = &amp;#34;abort&amp;#34;`, so this panic terminates the worker instead of being handled as a normal request error.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;#### Step 1.
starts a Granian ASGI server&lt;/p&gt;
&lt;p&gt;```python
# app.py
async def app(scope, receive, send):
    if scope[&amp;#34;type&amp;#34;] == &amp;#34;websocket&amp;#34;:
        await receive()
        await send({&amp;#34;type&amp;#34;: &amp;#34;websocket.accept&amp;#34;})
        return&lt;/p&gt;
&lt;p&gt;await send({&amp;#34;type&amp;#34;: &amp;#34;http.response.start&amp;#34;, &amp;#34;status&amp;#34;: 200, &amp;#34;headers&amp;#34;: []})
    await send({&amp;#34;type&amp;#34;: &amp;#34;http.response.body&amp;#34;, &amp;#34;body&amp;#34;: b&amp;#34;ok&amp;#34;})
```&lt;/p&gt;
&lt;p&gt;```bash
granian --interface asgi app:app --host 127.0.0.1 --port 8000
```&lt;/p&gt;
&lt;p&gt;#### Step 2.
sending a raw upgrade request with `Sec-WebSocket-Protocol: \x80\xff` reached this code path and caused the worker to abort.&lt;/p&gt;
&lt;p&gt;```python
# ws-subproto-crash.py
import base64, os, socket, sys&lt;/p&gt;
&lt;p&gt;host, port, path = sys.argv[1], int(sys.argv[2]), sy…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: granian&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Granian aborts a worker process when an unauthenticated client sends a WebSocket upgrade request whose `Sec-WebSocket-Protocol` header contains non-ASCII bytes.&lt;/p&gt;
&lt;p&gt;The crash happens in Granian&amp;#39;s WebSocket scope construction path, before the ASGI application is invoked.&lt;/p&gt;
&lt;p&gt;This is a single-request Denial Of Service against one worker. Repeating the request across workers takes the service offline.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;https://github.com/emmett-framework/granian/blob/bdd5b0fbbb2aca6f2f4c0d2700c244d190958035/src/asgi/utils.rs#L122-L125&lt;/p&gt;
&lt;p&gt;`HeaderValue::to_str()` returns `Err` for bytes outside visible ASCII. The subsequent `.unwrap()` panics.&lt;/p&gt;
&lt;p&gt;In release builds Granian sets `panic = &amp;#34;abort&amp;#34;`, so this panic terminates the worker instead of being handled as a normal request error.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;#### Step 1.
starts a Granian ASGI server&lt;/p&gt;
&lt;p&gt;```python
# app.py
async def app(scope, receive, send):
    if scope[&amp;#34;type&amp;#34;] == &amp;#34;websocket&amp;#34;:
        await receive()
        await send({&amp;#34;type&amp;#34;: &amp;#34;websocket.accept&amp;#34;})
        return&lt;/p&gt;
&lt;p&gt;await send({&amp;#34;type&amp;#34;: &amp;#34;http.response.start&amp;#34;, &amp;#34;status&amp;#34;: 200, &amp;#34;headers&amp;#34;: []})
    await send({&amp;#34;type&amp;#34;: &amp;#34;http.response.body&amp;#34;, &amp;#34;body&amp;#34;: b&amp;#34;ok&amp;#34;})
```&lt;/p&gt;
&lt;p&gt;```bash
granian --interface asgi app:app --host 127.0.0.1 --port 8000
```&lt;/p&gt;
&lt;p&gt;#### Step 2.
sending a raw upgrade request with `Sec-WebSocket-Protocol: \x80\xff` reached this code path and caused the worker to abort.&lt;/p&gt;
&lt;p&gt;```python
# ws-subproto-crash.py
import base64, os, socket, sys&lt;/p&gt;
&lt;p&gt;host, port, path = sys.argv[1], int(sys.argv[2]), sy…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vrg7-482j-p6f6</guid>
    </item>
    <item>
      <title>PYSEC-2026-2503 — Granian vulnerable to unauthenticated DoS via WebSocket subprotocol header panic</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2503</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: granian&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Granian aborts a worker process when an unauthenticated client sends a WebSocket upgrade request whose `Sec-WebSocket-Protocol` header contains non-ASCII bytes.&lt;/p&gt;
&lt;p&gt;The crash happens in Granian&amp;#39;s WebSocket scope construction path, before the ASGI application is invoked.&lt;/p&gt;
&lt;p&gt;This is a single-request Denial Of Service against one worker. Repeating the request across workers takes the service offline.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;https://github.com/emmett-framework/granian/blob/bdd5b0fbbb2aca6f2f4c0d2700c244d190958035/src/asgi/utils.rs#L122-L125&lt;/p&gt;
&lt;p&gt;`HeaderValue::to_str()` returns `Err` for bytes outside visible ASCII. The subsequent `.unwrap()` panics.&lt;/p&gt;
&lt;p&gt;In release builds Granian sets `panic = &amp;#34;abort&amp;#34;`, so this panic terminates the worker instead of being handled as a normal request error.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;#### Step 1.
starts a Granian ASGI server&lt;/p&gt;
&lt;p&gt;```python
# app.py
async def app(scope, receive, send):
    if scope[&amp;#34;type&amp;#34;] == &amp;#34;websocket&amp;#34;:
        await receive()
        await send({&amp;#34;type&amp;#34;: &amp;#34;websocket.accept&amp;#34;})
        return&lt;/p&gt;
&lt;p&gt;await send({&amp;#34;type&amp;#34;: &amp;#34;http.response.start&amp;#34;, &amp;#34;status&amp;#34;: 200, &amp;#34;headers&amp;#34;: []})
    await send({&amp;#34;type&amp;#34;: &amp;#34;http.response.body&amp;#34;, &amp;#34;body&amp;#34;: b&amp;#34;ok&amp;#34;})
```&lt;/p&gt;
&lt;p&gt;```bash
granian --interface asgi app:app --host 127.0.0.1 --port 8000
```&lt;/p&gt;
&lt;p&gt;#### Step 2.
sending a raw upgrade request with `Sec-WebSocket-Protocol: \x80\xff` reached this code path and caused the worker to abort.&lt;/p&gt;
&lt;p&gt;```python
# ws-subproto-crash.py
import base64, os, socket, sys&lt;/p&gt;
&lt;p&gt;host, port, path = sys.argv[1], int(sys.argv[2]), sy…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: granian&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Granian aborts a worker process when an unauthenticated client sends a WebSocket upgrade request whose `Sec-WebSocket-Protocol` header contains non-ASCII bytes.&lt;/p&gt;
&lt;p&gt;The crash happens in Granian&amp;#39;s WebSocket scope construction path, before the ASGI application is invoked.&lt;/p&gt;
&lt;p&gt;This is a single-request Denial Of Service against one worker. Repeating the request across workers takes the service offline.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;https://github.com/emmett-framework/granian/blob/bdd5b0fbbb2aca6f2f4c0d2700c244d190958035/src/asgi/utils.rs#L122-L125&lt;/p&gt;
&lt;p&gt;`HeaderValue::to_str()` returns `Err` for bytes outside visible ASCII. The subsequent `.unwrap()` panics.&lt;/p&gt;
&lt;p&gt;In release builds Granian sets `panic = &amp;#34;abort&amp;#34;`, so this panic terminates the worker instead of being handled as a normal request error.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;#### Step 1.
starts a Granian ASGI server&lt;/p&gt;
&lt;p&gt;```python
# app.py
async def app(scope, receive, send):
    if scope[&amp;#34;type&amp;#34;] == &amp;#34;websocket&amp;#34;:
        await receive()
        await send({&amp;#34;type&amp;#34;: &amp;#34;websocket.accept&amp;#34;})
        return&lt;/p&gt;
&lt;p&gt;await send({&amp;#34;type&amp;#34;: &amp;#34;http.response.start&amp;#34;, &amp;#34;status&amp;#34;: 200, &amp;#34;headers&amp;#34;: []})
    await send({&amp;#34;type&amp;#34;: &amp;#34;http.response.body&amp;#34;, &amp;#34;body&amp;#34;: b&amp;#34;ok&amp;#34;})
```&lt;/p&gt;
&lt;p&gt;```bash
granian --interface asgi app:app --host 127.0.0.1 --port 8000
```&lt;/p&gt;
&lt;p&gt;#### Step 2.
sending a raw upgrade request with `Sec-WebSocket-Protocol: \x80\xff` reached this code path and caused the worker to abort.&lt;/p&gt;
&lt;p&gt;```python
# ws-subproto-crash.py
import base64, os, socket, sys&lt;/p&gt;
&lt;p&gt;host, port, path = sys.argv[1], int(sys.argv[2]), sy…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2503</guid>
    </item>
  </channel>
</rss>
