CVE-2026-42545
Last modified
CVE-2026-42545 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Granian is a Rust HTTP server for Python applications. From 0.2.0 to 2.7.4, Granian aborts a worker process if a WSGI application returns an invalid HTTP response header name or value. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
Granian is a Rust HTTP server for Python applications. From 0.2.0 to 2.7.4, Granian aborts a worker process if a WSGI application returns an invalid HTTP response header name or value. The WSGI response conversion path uses .unwrap() on both the header name and header value constructors, so malformed output from the application becomes a process abort instead of a handled error. This vulnerability is fixed in 2.7.4.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-42545?
How severe is CVE-2026-42545?
How do I fix CVE-2026-42545?
Are you affected by CVE-2026-42545?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
