Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunked it would fall through and use the Content-Length header instead. According to the HTTP standard Transfer-Encoding should be a comma separated list, with the inner-most encoding first, followed by any further transfer codings, ending with chunked. Requests sent with: "Transfer-Encoding: gzip, chunked" would incorrectly get ignored, and the request would use a Content-Length header instead to determine the body size of the HTTP message. This could allow for Waitress to treat a single request as multiple requests in the case of HTTP pipelining. This issue is fixed in Waitress 1.4.0.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py3-waitress | Mar 24, 2020 | Dec 20, 2019 |
| Debian | — | Upgrade waitress | May 16, 2022 | Dec 20, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade python2-waitress | Aug 31, 2020 | Dec 20, 2019 |
| Oracle Solaris | — | Upgrade library/python-2/waitress to version 0.8.5-11.4.0.0.1.9.0 on Solaris 11.4Upgrade library/python/waitress-34 to version 1.4.3-11.4.21.0.1.69.0 on Solaris 11.4Upgrade library/python/waitress-35 to version 1.4.3-11.4.21.0.1.69.0 on Solaris 11.4Upgrade library/python/waitress-27 to version 1.4.3-11.4.21.0.1.69.0 on Solaris 11.4Upgrade library/python-2/waitress-27 to version 0.8.5-11.4.0.0.1.9.0 on Solaris 11.4Upgrade legacy/library/python/waitress-35 to version 1.4.3-11.4.21.0.1.69.0 on Solaris 11.4Upgrade library/python/waitress-26 to version 0.8.5-11.4.0.0.1.9.0 on Solaris 11.4Upgrade library/python/waitress to version 1.4.3-11.4.21.0.1.69.0 on Solaris 11.4Upgrade legacy/library/python/waitress-34 to version 1.4.3-11.4.21.0.1.69.0 on Solaris 11.4Upgrade library/python-2/waitress-26 to version 0.8.5-11.4.0.0.1.9.0 on Solaris 11.4 | Jan 19, 2021 | Dec 20, 2019 |
| Suse | — | Upgrade python2-waitressUpgrade python3-waitress | Nov 12, 2020 | Dec 20, 2019 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Dec 20, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub