CVE-2018-1000164
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0.
- Gunicorn
- = 19.4.5
- Fix
- Available
- CVSS 3.0
- 7.5 HIGH
- EPSS
- 2.5% (83th percentile)
- Weakness
- CWE-93
- NVD status
- Modified
- Published
- 2018-04-18
CVE-2018-1000164 at NVD
No indexed exploits for CVE-2018-1000164 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2018-1000164 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.