gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gunicorn | Apr 30, 2018 | Apr 18, 2018 |
| Freebsd | — | Upgrade py37-gunicornUpgrade py36-gunicornUpgrade py35-gunicornUpgrade py27-gunicorn | Mar 5, 2019 | Mar 5, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 18, 2018 |
| Suse | — | Upgrade python3-gunicornUpgrade python3-gunicorn-docUpgrade python-gunicornUpgrade python-gunicorn-doc | Mar 2, 2020 | Apr 17, 2018 |
| Ubuntu | — | Upgrade python-gunicornUpgrade python3-gunicornUpgrade gunicornUpgrade gunicorn3 | Jun 20, 2019 | Apr 18, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub