gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gunicorn | Apr 30, 2018 | Apr 18, 2018 |
| Freebsd | — | Upgrade py35-gunicornUpgrade py27-gunicornUpgrade py36-gunicornUpgrade py37-gunicorn | Mar 5, 2019 | Mar 5, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 18, 2018 |
| Suse | — | Upgrade python3-gunicorn-docUpgrade python-gunicorn-docUpgrade python-gunicornUpgrade python3-gunicorn | Mar 2, 2020 | Apr 17, 2018 |
| Ubuntu | — | Upgrade python-gunicornUpgrade python3-gunicornUpgrade gunicornUpgrade gunicorn3 | Jun 20, 2019 | Apr 18, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub