CVE-2026-24489Patch

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Gakido is a Python HTTP client focused on browser impersonation and anti-bot evasion. A vulnerability was discovered in Gakido prior to version 0.1.1 that allowed HTTP header injection through CRLF (Carriage Return Line Feed) sequences in user-supplied header values and names. When making HTTP requests with user-controlled header values containing `\r\n` (CRLF), `\n` (LF), or `\x00` (null byte) characters, an attacker could inject arbitrary HTTP headers into the request. The fix in version 0.1.1 adds a `_sanitize_header()` function that strips `\r`, `\n`, and `\x00` characters from both header names and values before they are included in HTTP requests.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-93CWE-113

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-03); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-03: 1Mentions · 2026-02-09: 1Patch / Workaround · 2026-02-03: 1Technical Details · 2026-02-03: 1Technical Details · 2026-02-09: 102-0302-09
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-031
Patch1
2026-02-091
Disclosure1
Full discourse2 posts
  • iototsecnews@iototsecnews
    Disclosure

    Gakido の CRLF Injection 脆弱性 CVE-2026-24489 が FIX:HTTP レスポンスの不正操作の恐れ https://iototsecnews.jp/2026/02/02/gakido-crlf-injection-vulnerability-let-attackers-bypass-security-controls/ この問題の原因は、プログラムが外部から受け取った文字を “ただのデータ” としてではなく、通信のルールを決める “制御命令” として、誤って解釈してしまったことにあります。具体的には、Gakido というライブラリの中で、改行を意味する CRLF “\r\n” などの特殊な文字を取り除く処理が漏れていました。この脆弱性 CVE-2026-24489 を悪用する攻撃者は、入力した改行コードを通信プロトコルに紛れ込ませ、本来は存在しないはずの偽のヘッダを追加できる状態を作り出していました。こうした “入力値の確認不足” が、セッションの乗っ取りやキャッシュの汚染といった、深刻なトラブルを招くきっかけとなります。ご利用のチームは、ご注意ください。 #CVE202624489 #Gakido #Python #Vulnerability

    Post summary

    The post announces a CRLF injection vulnerability (CVE‑2026‑24489) in the Gakido library, describing how attackers could inject malicious headers to hijack sessions, but does not provide a PoC, exploit, or patch details.

    01001168
    483 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Critical vulnerability in Gakido HTTP client library (CVE-2026-24489) allows attackers to inject arbitrary HTTP headers. Users urged to update immediately. Link: https://thedailytechfeed.com/critical-flaw-in-gakido-library-enables-unauthorized-http-header-injection-users-urged-to-update-immediately/ #Security #Update #CVE #Exploit #Patch #Threat #Library #Injection #Headers #Technology #Software #Development #Risk #Protection #Attack #Bug #Fix #Code #Alert #Internet

    Post summary

    The tweet highlights a critical CVE that permits arbitrary HTTP header injection and urges users to apply a patch immediately.

    0000040
    238 followersView on X

Explore more