Sanic Project maintains a focused Python web framework for building asynchronous web applications, with the durable vulnerability signal centered on path-traversal issues in file-serving and request-handling functionality. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sanic Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-16762HIGH Sanic before 0.5.1 allows reading arbitrary files with directory traversal, as demonstrated by the /static/..%2f substring. | Nov 10, 2017 | 7.5 | 25 | NO | NO |
CVE-2022-35920HIGH Sanic is an opensource python web server/framework. Affected versions of sanic allow access to lateral directories when using `app.static` if using encoded `%2F` URLs. Parent direc | Aug 1, 2022 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sanic Project.
Media articles that mention a CVE ID that affects a product developed by Sanic Project — matched by CVE ID, not by vendor name.