CreaRack-SL

Incident: Daphne CVEs PYSEC-2026-213 (DoS) y PYSEC-2026-214 (Header Injection)

Resumen

Daphne 4.2.1 contiene dos CVEs críticas detectadas por pip-audit:

  1. PYSEC-2026-213: Denial of Service (DoS) en manejo de WebSocket.

    • Score CVSS: 7.5 (ALTA).
    • Descripción: Attacker puede enviar frames malformados que causan crash o exhaustion de memoria.
  2. PYSEC-2026-214: Header Injection en respuesta HTTP.

    • Score CVSS: 5.3 (MEDIA).
    • Descripción: Attacker puede inyectar encabezados HTTP malformados (e.g., \r\n) en la respuesta, causando cache poisoning o session hijacking.

Impacto en CreaRack Pro

Componentes afectados:

  • WebSocket handler (real-time metrics, agent communication).
  • HTTP headers en todas las responses.

Riesgo de ataque:

  • Cliente no autenticado puede crashear el servidor o quedar en DoS indefinido (PYSEC-2026-213).
  • Attacker autenticado o MITM puede inyectar headers (PYSEC-2026-214).

Severidad en producción: CRÍTICA (DoS en WebSocket, infraestructura crítica para monitoring).

Remediación

Acción: Actualizar daphne 4.2.1 → 4.2.2 (ya aplicada en este commit).

# requirements/base.txt (o similar)
daphne>=4.2.2  # Fix PYSEC-2026-213, PYSEC-2026-214

Testing:

  • Ejecutar pip-audit post-deploy para verificar resolución.
  • Smoke test: WebSocket connection from agent → enviar frame malformado → debe rechazar sin crash.
  • HTTP header test: inject \r\nX-Injected: true → debe sanitizar.

Timeline

  • 2026-07-10 13:17: Detectado en pip-audit durante FASE 0 de auditoria.
  • 2026-07-10 13:30: Bump aplicado en commit ec452b2.
  • 2026-07-10 (EOD): Deploy a staging para validar.
  • 2026-07-11: Deploy a producción si smoke tests pasan.

Referencias

Véase también

  • [[decision—20260710—auditoria-2026-07-fase-1]]
  • [[incident—20260710—rls-gap-tablas-nuevas]]