ROSECURIFY
~/ advisories/ RO-26-005

Gakido - CRLF Injection

HappyHackingSpace vendorGakido product< 0.1.1-1bc6019 version

Overview #

A vulnerability was discovered in Gakido that allowed HTTP header injection through CRLF (Carriage Return Line Feed) sequences in user-supplied header values and names.

Vulnerability Details #

When making HTTP requests with user-controlled header values containing \r\n (CRLF), \n (LF), or \x00 (null byte) characters, an attacker could inject arbitrary HTTP headers into the request.

Affected Code: The vulnerability existed in the header processing logic where user-supplied headers were not sanitized before being sent in HTTP requests.

Impact #

An attacker who can control header values passed to Gakido's Client.get(), Client.post(), or other request methods could:

Proof of Concept #

python
from gakido import Client

# Before fix: X-Injected header would be sent as a separate header
c = Client(impersonate="chrome_120")
r = c.get("https://httpbin.org/headers", headers={
    "User-Agent": "test\r\nX-Injected: pwned"
})

References #

Timeline #

Credits: Omar Kurt