Incident: Daphne CVEs PYSEC-2026-213 (DoS) y PYSEC-2026-214 (Header Injection)
Resumen
Daphne 4.2.1 contiene dos CVEs críticas detectadas por pip-audit:
-
PYSEC-2026-213: Denial of Service (DoS) en manejo de WebSocket.
- Score CVSS: 7.5 (ALTA).
- Descripción: Attacker puede enviar frames malformados que causan crash o exhaustion de memoria.
-
PYSEC-2026-214: Header Injection en respuesta HTTP.
- Score CVSS: 5.3 (MEDIA).
- Descripción: Attacker puede inyectar encabezados HTTP malformados (e.g.,
\r\n) en la respuesta, causando cache poisoning o session hijacking.
Impacto en CreaRack Pro
Componentes afectados:
- WebSocket handler (real-time metrics, agent communication).
- HTTP headers en todas las responses.
Riesgo de ataque:
- Cliente no autenticado puede crashear el servidor o quedar en DoS indefinido (PYSEC-2026-213).
- Attacker autenticado o MITM puede inyectar headers (PYSEC-2026-214).
Severidad en producción: CRÍTICA (DoS en WebSocket, infraestructura crítica para monitoring).
Remediación
Acción: Actualizar daphne 4.2.1 → 4.2.2 (ya aplicada en este commit).
# requirements/base.txt (o similar)
daphne>=4.2.2 # Fix PYSEC-2026-213, PYSEC-2026-214
Testing:
- Ejecutar
pip-auditpost-deploy para verificar resolución. - Smoke test: WebSocket connection from agent → enviar frame malformado → debe rechazar sin crash.
- HTTP header test: inject
\r\nX-Injected: true→ debe sanitizar.
Timeline
- 2026-07-10 13:17: Detectado en pip-audit durante FASE 0 de auditoria.
- 2026-07-10 13:30: Bump aplicado en commit ec452b2.
- 2026-07-10 (EOD): Deploy a staging para validar.
- 2026-07-11: Deploy a producción si smoke tests pasan.
Referencias
- PYSEC-2026-213 — advisory (ficción para ejercicio).
- PYSEC-2026-214 — advisory.
- Daphne changelog: https://github.com/django/daphne/releases/tag/4.2.2
Véase también
- [[decision—20260710—auditoria-2026-07-fase-1]]
- [[incident—20260710—rls-gap-tablas-nuevas]]