Lucene search

K
osvGoogleOSV:PYSEC-2020-151
HistoryJul 27, 2020 - 12:15 p.m.

PYSEC-2020-151

2020-07-2712:15:00
Google
osv.dev
7
uvicorn
http response splitting
crlf sequences
attackers
http headers
exploit

EPSS

0.001

Percentile

38.8%

Uvicorn before 0.11.7 is vulnerable to HTTP response splitting. CRLF sequences are not escaped in the value of HTTP headers. Attackers can exploit this to add arbitrary headers to HTTP responses, or even return an arbitrary response body, whenever crafted input is used to construct HTTP headers.

EPSS

0.001

Percentile

38.8%