Vulnerability PYSEC-2017-40
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
8 years ago
November 10, 2017 at 09:29 AM UTC
No summary available
0.1.0 - 0.5.0
0.1.0 - 0.5.0
Details
Sanic before 0.5.1 allows reading arbitrary files with directory traversal, as demonstrated by the /static/..%2f substring.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
14 days ago
sanic chunked trailer request smuggling allows hidden second request execution
0.1.0 - 24.12.0 and 25.12.0 GHSA-wmj6-g64g-j7q5
0.1.0 - 24.12.0 and 25.12.0 GHSA-wmj6-g64g-j7q5
High Risk
2 months ago
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
0.1.0 - 20.12.6 and 21.3.0 - 21.12.1 and 22.3.0 - 22.6.0 PYSEC-2026-918
0.1.0 - 20.12.6 and 21.3.0 - 21.12.1 and 22.3.0 - 22.6.0 PYSEC-2026-918
High Risk
4 years ago
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
0.1.0 - 20.12.6 and 21.3.0 - 21.12.1 and 22.3.0 - 22.6.0 GHSA-8cw9-5hmv-77w6
0.1.0 - 20.12.6 and 21.3.0 - 21.12.1 and 22.3.0 - 22.6.0 GHSA-8cw9-5hmv-77w6
High Risk
4 years ago
Sanic arbitrary file read and directory traversal
0.1.0 - 0.5.0 GHSA-mpmf-hr8p-p49g
0.1.0 - 0.5.0 GHSA-mpmf-hr8p-p49g
High Risk
4 years ago
Server crash if running Python 3.10 w/ Sanic 20.12
0.1.7 - 20.12.5 GHSA-7p79-6x2v-5h88
0.1.7 - 20.12.5 GHSA-7p79-6x2v-5h88
Impacted packages
Timeline
Published
8 years ago
November 10, 2017 at 09:29 AM UTC
Fixed (0.5.1)
9 years ago
April 14, 2017 at 07:04 PM UTC
Last Modified
3 months ago
June 10, 2026 at 05:02 PM UTC