blacksheep
Fast web framework for Python asyncio
Activity
- Latest release
- 3mo ago
- Total releases
- 108
- Cadence
- ~9 days
- Last 12 months
- 16
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Nov 24, 2018
| Version | Released | |
|---|---|---|
2.6.3
patch
| ||
2.6.2
patch
| ||
2.6.1
patch
| ||
2.6.0
minor
| ||
2.5.1
patch
| ||
2.5.1a2
pre
| ||
2.5.1a1
pre
| ||
2.5.1a0
pre
| ||
2.5.0
minor
| ||
2.4.6
patch
| ||
2.4.5
patch
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.4.4
patch
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.4.4a2
pre
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.4.4a0
pre
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.4.3
patch
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.4.2
patch
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.4.1
patch
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.4.0
minor
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.3.2
patch
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.3.1
patch
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.3.1a1
pre
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.3.0
minor
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.3.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.2.0
minor
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.2.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.1.0
minor
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.1.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.0.8
patch
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.0.7
patch
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.0.6
patch
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.0.5
patch
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.2.20
patch
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.0.4
patch
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.2.19
patch
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.0.3
patch
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.0.2
patch
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.0.1
patch
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.0.0
major
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.0a12
pre
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.0a11
pre
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.0a10
pre
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.2.18
patch
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.0a9
pre
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.0a8
pre
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.2.17
patch
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.2.16
patch
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.2.15
patch
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.0a7
pre
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.0a6
pre
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.2.14
patch
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.2.13
patch
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.0a5
pre
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.2.12
patch
1 CVE
CVE-2026-22779
PYSEC-2026-1222
GHSA-6pw3-h7xf-x4gp
Jul 07, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Low
Network
Low
None
None
ImpactThe HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers. The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. Attack vector: Applications using user input in HTTP client requests (method, URL, headers). PatchesUsers who use the HTTP Client in BlackSheep should upgrade to WorkaroundsIf users handle headers from untrusted parties, they might reject values for header names and values that contain carriage returns. Referenceshttps://owasp.org/www-community/vulnerabilities/CRLF_Injection Affected versions
0.0.1
0.0.2
0.0.4
0.0.5
0.0.6
0.0.7
0.0.9
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
+ 86 more Show less
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0a0
2.0a1
2.0a10
2.0a11
2.0a12
2.0a2
2.0a3
2.0a4
2.0a5
2.0a6
2.0a7
2.0a8
2.0a9
2.1.0
2.2.0
2.3.0
2.3.1
2.3.1a1
2.3.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.4a0
2.4.4a2
2.4.5
Fixed in
2.4.6
References
Updated Jul 07, 2026 · Source: OSV.dev |