Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22225
HistoryDec 23, 2019 - 7:27 a.m.

HTTP Request Smuggling

2019-12-2307:27:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
36

0.003 Low

EPSS

Percentile

68.2%

waitress is vulnerable HTTP request smuggling. The vulnerability exists because the library mishandled HTTP request header by not correctly parsing the Transfer-Encoding header, causing the parser to use Content-Length header instead to determine the HTTP message body size, ignoring the requests that are sent with Transfer-Encoding: gzip, chunked and treating single request as multiple requests in the case of HTTP pipelining.