{"id":"CVE-2022-35920","aliases":["GHSA-8cw9-5hmv-77w6","PYSEC-2026-918"],"title":"sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs","summary":"sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs","severity":"high","cvss":8.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L","vendor":"sanic","product":"sanic","ecosystem":"pip","affected":["sanic >= 22.0.0, < 22.6.1","sanic >= 21.0.0, < 21.12.2","sanic < 20.12.7"],"patched":["sanic 22.6.1","sanic 21.12.2","sanic 20.12.7"],"published":"2022-08-06","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-8cw9-5hmv-77w6","references":[{"url":"https://github.com/sanic-org/sanic/security/advisories/GHSA-8cw9-5hmv-77w6"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-35920"},{"url":"https://github.com/sanic-org/sanic/issues/2478"},{"url":"https://github.com/sanic-org/sanic/pull/2495"},{"url":"https://github.com/sanic-org/sanic"}],"tags":["osv","pip"],"epss":0.0114,"epssPercentile":0.64733,"ingestedAt":"2026-07-08T18:25:47.459Z","slug":"CVE-2022-35920","body":"## Overview\n\n### Impact\nAccess to lateral directories when using `app.static` if using encoded `%2F` URLs. Parent directory traversal is not impacted.\n\n### Patches\n- v20.12.7 (LTS)\n- v21.12.2 (LTS)\n- v22.6.1\n\n### References\nhttps://github.com/sanic-org/sanic/issues/2478\nhttps://github.com/sanic-org/sanic/pull/2495\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [the community forums](https://community.sanicframework.org/)\n* Ping us on [the Discord server](https://discord.gg/FARQzAEMAA)\n\n\n\n## Affected packages\n\n- `sanic >= 22.0.0, < 22.6.1`\n- `sanic >= 21.0.0, < 21.12.2`\n- `sanic < 20.12.7`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `sanic 22.6.1`\n- `sanic 21.12.2`\n- `sanic 20.12.7`","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":45.7,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}