Description
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0.
References (5)
Scores
CVSS v3
7.5
EPSS
0.0148
EPSS Percentile
81.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-93
Status
published
Products (4)
debian/debian_linux
7.0
debian/debian_linux
8.0
gunicorn/gunicorn
19.4.5
pypi/gunicorn
0 - 19.5.0PyPI
Published
Apr 18, 2018
Tracked Since
Feb 18, 2026