{"id":"CVE-2022-35920","summary":"Improper Limitation of a Pathname to a Restricted Directory in sanic","details":"Sanic is an opensource python web server/framework. Affected versions of sanic allow access to lateral directories when using `app.static` if using encoded `%2F` URLs. Parent directory traversal is not impacted. Users are advised to upgrade. There is no known workaround for this issue.","aliases":["GHSA-8cw9-5hmv-77w6","PYSEC-2026-918"],"modified":"2026-08-12T03:30:15.808471255Z","published":"2022-08-01T21:35:27Z","database_specific":{"cwe_ids":["CWE-22"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/35xxx/CVE-2022-35920.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/35xxx/CVE-2022-35920.json"},{"type":"ADVISORY","url":"https://github.com/sanic-org/sanic/security/advisories/GHSA-8cw9-5hmv-77w6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-35920"},{"type":"REPORT","url":"https://github.com/sanic-org/sanic/issues/2478"},{"type":"FIX","url":"https://github.com/sanic-org/sanic/pull/2495"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sanic-org/sanic","events":[{"introduced":"0"},{"fixed":"05002d7ee4f2254bcf054d7157cf73af01e54255"},{"fixed":"0b750593da14e6b63e5b6cc89d9765f11e5b2469"},{"fixed":"daa1f8f2d53f4ead07b92dd4decdc2bb44a2f841"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:sanic_project:sanic:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"20.12.7"},{"introduced":"21.0.0"},{"fixed":"21.12.2"},{"introduced":"22.0.0"},{"fixed":"22.6.1"}]}}],"versions":["v20.12.6","v21.12.1","v22.6.0","v22.3.1","v22.3.0","v20.12.5","v20.12.4","v21.12.0","v21.9.1","v21.9.0","v21.6.0","v20.12.3","v21.3.2","v21.3.1","v21.3.0","v20.12.2","v20.12.1","v20.12.0","v20.9.1","v20.9.0","v20.6.3","v20.3.0","v19.12.1","v19.9.0","v19.6.3","v19.6.2","v19.6.1","v19.6.0","19.03.1","19.3","18.12.0","0.8.3","0.8.2","0.8.1","0.8.0","0.7.0","0.6.0","0.5.4","0.5.3","0.5.2","0.5.1","0.5.0","0.4.1","0.4.0","0.3.1","0.3.0","0.2.0","0.1.9","0.1.8","0.1.7","0.1.6","0.1.5","0.1.4","0.1.3","0.1.2"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-35920.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"}]}