Lucene search

K
osvGoogleOSV:GHSA-F97H-2PFX-F59F
HistoryJul 29, 2020 - 6:07 p.m.

HTTP response splitting in uvicorn

2020-07-2918:07:20
Google
osv.dev
12
uvicorn
vulnerability
http response splitting
crlf sequences
http headers
attackers

EPSS

0.001

Percentile

38.8%

Uvicorn before 0.11.7 is vulnerable to HTTP response splitting. CRLF sequences are not escaped in the value of HTTP headers. Attackers can exploit exploit this to add arbitrary headers to HTTP responses, or even return an arbitrary response body, whenever crafted input is used to construct HTTP headers.

EPSS

0.001

Percentile

38.8%