sanic
A web server and web framework that's written to go fast. Build fast. Run fast.
Activity
- Latest release
- 3mo ago
- Total releases
- 84
- Cadence
- ~27 days
- Last 12 months
- 3
Details
- License
- MIT
- First release
- Oct 15, 2016
| Version | Released | |
|---|---|---|
25.12.1
patch
| ||
24.12.1
patch
| ||
25.12.0
minor
| ||
25.3.0
major
| ||
24.12.0
minor
| ||
24.6.0
major
| ||
23.12.2
patch
| ||
23.12.1
patch
| ||
23.12.0
minor
| ||
23.6.0
minor
| ||
23.3.0
major
| ||
22.12.0
minor
| ||
22.9.1
patch
| ||
22.9.0
minor
| ||
22.6.2
patch
| ||
22.6.1
patch
| ||
21.12.2
patch
| ||
20.12.7
patch
| ||
22.6.0
minor
1 CVE
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev | ||
22.3.2
patch
1 CVE
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev | ||
22.3.1
patch
1 CVE
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev | ||
22.3.0
major
1 CVE
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev | ||
20.12.6
patch
1 CVE
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev | ||
20.12.5
patch
2 CVEs
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev
GHSA-7p79-6x2v-5h88
Feb 16, 2022
Server crash if running Python 3.10 w/ Sanic 20.12
High
!!! ONLY APPLIES TO VERSIONS PRIOR TO Sanic v20.12 WHEN USING Python 3.10 !!! Sanic v20.12 officially supports Python versions 3.6, 3.7, 3.8, and 3.9. However, if you accidentally run it with version 3.10 (which is not supported by Sanic 20.12), your server is prone to crashing on an incoming web request. ImpactAnyone running Sanic server between 0.1.7 and 20.12 using Python 3.10. PatchesWorkaroundsUse a supported version of Python (v3.6 - v3.9) References
For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
+ 30 more Show less
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
Fixed in
20.12.6
References Updated Dec 05, 2024 · Source: OSV.dev | ||
21.12.1
patch
1 CVE
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev | ||
21.12.0
minor
1 CVE
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev | ||
21.9.3
patch
1 CVE
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev | ||
21.9.2
patch
1 CVE
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev | ||
21.9.1
patch
1 CVE
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev | ||
20.12.4
patch
2 CVEs
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev
GHSA-7p79-6x2v-5h88
Feb 16, 2022
Server crash if running Python 3.10 w/ Sanic 20.12
High
!!! ONLY APPLIES TO VERSIONS PRIOR TO Sanic v20.12 WHEN USING Python 3.10 !!! Sanic v20.12 officially supports Python versions 3.6, 3.7, 3.8, and 3.9. However, if you accidentally run it with version 3.10 (which is not supported by Sanic 20.12), your server is prone to crashing on an incoming web request. ImpactAnyone running Sanic server between 0.1.7 and 20.12 using Python 3.10. PatchesWorkaroundsUse a supported version of Python (v3.6 - v3.9) References
For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
+ 30 more Show less
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
Fixed in
20.12.6
References Updated Dec 05, 2024 · Source: OSV.dev | ||
21.9.0
minor
1 CVE
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev | ||
21.6.2
patch
1 CVE
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev | ||
21.6.1
patch
1 CVE
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev | ||
21.6.0
minor
1 CVE
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev | ||
21.3.4
patch
1 CVE
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev | ||
21.3.2
patch
1 CVE
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev | ||
21.3.1
patch
1 CVE
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev | ||
21.3.0
major
1 CVE
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev | ||
20.12.3
patch
2 CVEs
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev
GHSA-7p79-6x2v-5h88
Feb 16, 2022
Server crash if running Python 3.10 w/ Sanic 20.12
High
!!! ONLY APPLIES TO VERSIONS PRIOR TO Sanic v20.12 WHEN USING Python 3.10 !!! Sanic v20.12 officially supports Python versions 3.6, 3.7, 3.8, and 3.9. However, if you accidentally run it with version 3.10 (which is not supported by Sanic 20.12), your server is prone to crashing on an incoming web request. ImpactAnyone running Sanic server between 0.1.7 and 20.12 using Python 3.10. PatchesWorkaroundsUse a supported version of Python (v3.6 - v3.9) References
For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
+ 30 more Show less
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
Fixed in
20.12.6
References Updated Dec 05, 2024 · Source: OSV.dev | ||
20.12.2
patch
2 CVEs
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev
GHSA-7p79-6x2v-5h88
Feb 16, 2022
Server crash if running Python 3.10 w/ Sanic 20.12
High
!!! ONLY APPLIES TO VERSIONS PRIOR TO Sanic v20.12 WHEN USING Python 3.10 !!! Sanic v20.12 officially supports Python versions 3.6, 3.7, 3.8, and 3.9. However, if you accidentally run it with version 3.10 (which is not supported by Sanic 20.12), your server is prone to crashing on an incoming web request. ImpactAnyone running Sanic server between 0.1.7 and 20.12 using Python 3.10. PatchesWorkaroundsUse a supported version of Python (v3.6 - v3.9) References
For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
+ 30 more Show less
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
Fixed in
20.12.6
References Updated Dec 05, 2024 · Source: OSV.dev | ||
19.12.5
patch
2 CVEs
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev
GHSA-7p79-6x2v-5h88
Feb 16, 2022
Server crash if running Python 3.10 w/ Sanic 20.12
High
!!! ONLY APPLIES TO VERSIONS PRIOR TO Sanic v20.12 WHEN USING Python 3.10 !!! Sanic v20.12 officially supports Python versions 3.6, 3.7, 3.8, and 3.9. However, if you accidentally run it with version 3.10 (which is not supported by Sanic 20.12), your server is prone to crashing on an incoming web request. ImpactAnyone running Sanic server between 0.1.7 and 20.12 using Python 3.10. PatchesWorkaroundsUse a supported version of Python (v3.6 - v3.9) References
For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
+ 30 more Show less
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
Fixed in
20.12.6
References Updated Dec 05, 2024 · Source: OSV.dev | ||
20.12.1
patch
2 CVEs
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev
GHSA-7p79-6x2v-5h88
Feb 16, 2022
Server crash if running Python 3.10 w/ Sanic 20.12
High
!!! ONLY APPLIES TO VERSIONS PRIOR TO Sanic v20.12 WHEN USING Python 3.10 !!! Sanic v20.12 officially supports Python versions 3.6, 3.7, 3.8, and 3.9. However, if you accidentally run it with version 3.10 (which is not supported by Sanic 20.12), your server is prone to crashing on an incoming web request. ImpactAnyone running Sanic server between 0.1.7 and 20.12 using Python 3.10. PatchesWorkaroundsUse a supported version of Python (v3.6 - v3.9) References
For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
+ 30 more Show less
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
Fixed in
20.12.6
References Updated Dec 05, 2024 · Source: OSV.dev | ||
20.12.0
minor
2 CVEs
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev
GHSA-7p79-6x2v-5h88
Feb 16, 2022
Server crash if running Python 3.10 w/ Sanic 20.12
High
!!! ONLY APPLIES TO VERSIONS PRIOR TO Sanic v20.12 WHEN USING Python 3.10 !!! Sanic v20.12 officially supports Python versions 3.6, 3.7, 3.8, and 3.9. However, if you accidentally run it with version 3.10 (which is not supported by Sanic 20.12), your server is prone to crashing on an incoming web request. ImpactAnyone running Sanic server between 0.1.7 and 20.12 using Python 3.10. PatchesWorkaroundsUse a supported version of Python (v3.6 - v3.9) References
For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
+ 30 more Show less
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
Fixed in
20.12.6
References Updated Dec 05, 2024 · Source: OSV.dev | ||
19.12.4
patch
2 CVEs
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev
GHSA-7p79-6x2v-5h88
Feb 16, 2022
Server crash if running Python 3.10 w/ Sanic 20.12
High
!!! ONLY APPLIES TO VERSIONS PRIOR TO Sanic v20.12 WHEN USING Python 3.10 !!! Sanic v20.12 officially supports Python versions 3.6, 3.7, 3.8, and 3.9. However, if you accidentally run it with version 3.10 (which is not supported by Sanic 20.12), your server is prone to crashing on an incoming web request. ImpactAnyone running Sanic server between 0.1.7 and 20.12 using Python 3.10. PatchesWorkaroundsUse a supported version of Python (v3.6 - v3.9) References
For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
+ 30 more Show less
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
Fixed in
20.12.6
References Updated Dec 05, 2024 · Source: OSV.dev | ||
20.9.1
patch
2 CVEs
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev
GHSA-7p79-6x2v-5h88
Feb 16, 2022
Server crash if running Python 3.10 w/ Sanic 20.12
High
!!! ONLY APPLIES TO VERSIONS PRIOR TO Sanic v20.12 WHEN USING Python 3.10 !!! Sanic v20.12 officially supports Python versions 3.6, 3.7, 3.8, and 3.9. However, if you accidentally run it with version 3.10 (which is not supported by Sanic 20.12), your server is prone to crashing on an incoming web request. ImpactAnyone running Sanic server between 0.1.7 and 20.12 using Python 3.10. PatchesWorkaroundsUse a supported version of Python (v3.6 - v3.9) References
For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
+ 30 more Show less
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
Fixed in
20.12.6
References Updated Dec 05, 2024 · Source: OSV.dev | ||
19.12.3
patch
2 CVEs
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev
GHSA-7p79-6x2v-5h88
Feb 16, 2022
Server crash if running Python 3.10 w/ Sanic 20.12
High
!!! ONLY APPLIES TO VERSIONS PRIOR TO Sanic v20.12 WHEN USING Python 3.10 !!! Sanic v20.12 officially supports Python versions 3.6, 3.7, 3.8, and 3.9. However, if you accidentally run it with version 3.10 (which is not supported by Sanic 20.12), your server is prone to crashing on an incoming web request. ImpactAnyone running Sanic server between 0.1.7 and 20.12 using Python 3.10. PatchesWorkaroundsUse a supported version of Python (v3.6 - v3.9) References
For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
+ 30 more Show less
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
Fixed in
20.12.6
References Updated Dec 05, 2024 · Source: OSV.dev | ||
20.9.0
minor
2 CVEs
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev
GHSA-7p79-6x2v-5h88
Feb 16, 2022
Server crash if running Python 3.10 w/ Sanic 20.12
High
!!! ONLY APPLIES TO VERSIONS PRIOR TO Sanic v20.12 WHEN USING Python 3.10 !!! Sanic v20.12 officially supports Python versions 3.6, 3.7, 3.8, and 3.9. However, if you accidentally run it with version 3.10 (which is not supported by Sanic 20.12), your server is prone to crashing on an incoming web request. ImpactAnyone running Sanic server between 0.1.7 and 20.12 using Python 3.10. PatchesWorkaroundsUse a supported version of Python (v3.6 - v3.9) References
For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
+ 30 more Show less
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
Fixed in
20.12.6
References Updated Dec 05, 2024 · Source: OSV.dev | ||
20.6.3
patch
2 CVEs
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev
GHSA-7p79-6x2v-5h88
Feb 16, 2022
Server crash if running Python 3.10 w/ Sanic 20.12
High
!!! ONLY APPLIES TO VERSIONS PRIOR TO Sanic v20.12 WHEN USING Python 3.10 !!! Sanic v20.12 officially supports Python versions 3.6, 3.7, 3.8, and 3.9. However, if you accidentally run it with version 3.10 (which is not supported by Sanic 20.12), your server is prone to crashing on an incoming web request. ImpactAnyone running Sanic server between 0.1.7 and 20.12 using Python 3.10. PatchesWorkaroundsUse a supported version of Python (v3.6 - v3.9) References
For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
+ 30 more Show less
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
Fixed in
20.12.6
References Updated Dec 05, 2024 · Source: OSV.dev | ||
20.6.2
patch
2 CVEs
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev
GHSA-7p79-6x2v-5h88
Feb 16, 2022
Server crash if running Python 3.10 w/ Sanic 20.12
High
!!! ONLY APPLIES TO VERSIONS PRIOR TO Sanic v20.12 WHEN USING Python 3.10 !!! Sanic v20.12 officially supports Python versions 3.6, 3.7, 3.8, and 3.9. However, if you accidentally run it with version 3.10 (which is not supported by Sanic 20.12), your server is prone to crashing on an incoming web request. ImpactAnyone running Sanic server between 0.1.7 and 20.12 using Python 3.10. PatchesWorkaroundsUse a supported version of Python (v3.6 - v3.9) References
For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
+ 30 more Show less
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
Fixed in
20.12.6
References Updated Dec 05, 2024 · Source: OSV.dev | ||
20.6.1
patch
2 CVEs
CVE-2022-35920
PYSEC-2026-918
GHSA-8cw9-5hmv-77w6
Jul 06, 2026
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactAccess to lateral directories when using Patches
Referenceshttps://github.com/sanic-org/sanic/issues/2478 https://github.com/sanic-org/sanic/pull/2495 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
+ 54 more Show less
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.12.6
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
21.12.0
21.12.1
21.3.0
21.3.1
21.3.2
21.3.4
21.6.0
21.6.1
21.6.2
21.9.0
21.9.1
21.9.2
21.9.3
22.3.0
22.3.1
22.3.2
22.6.0
Fixed in
20.12.7
21.12.2
22.6.1
References Updated Jul 07, 2026 · Source: OSV.dev
GHSA-7p79-6x2v-5h88
Feb 16, 2022
Server crash if running Python 3.10 w/ Sanic 20.12
High
!!! ONLY APPLIES TO VERSIONS PRIOR TO Sanic v20.12 WHEN USING Python 3.10 !!! Sanic v20.12 officially supports Python versions 3.6, 3.7, 3.8, and 3.9. However, if you accidentally run it with version 3.10 (which is not supported by Sanic 20.12), your server is prone to crashing on an incoming web request. ImpactAnyone running Sanic server between 0.1.7 and 20.12 using Python 3.10. PatchesWorkaroundsUse a supported version of Python (v3.6 - v3.9) References
For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.4
+ 30 more Show less
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
18.12.0
19.12.0
19.12.2
19.12.3
19.12.4
19.12.5
19.3.1
19.6.0
19.6.2
19.6.3
19.9.0
20.12.0
20.12.1
20.12.2
20.12.3
20.12.4
20.12.5
20.3.0
20.6.0
20.6.1
20.6.2
20.6.3
20.9.0
20.9.1
Fixed in
20.12.6
References Updated Dec 05, 2024 · Source: OSV.dev |