Waitress
Pylons · 5 CVEs
Waitress has request processing race condition in HTTP pipelining with invalid first request
Oct 29, 2024
Waitress has a denial of service leading to high CPU usage/resource exhaustion
Oct 29, 2024
Uncaught Exception (due to a data race) leads to process termination in Waitress
May 31, 2022
HTTP Request Smuggling in waitress
Mar 17, 2022
Catastrophic backtracking in regex allows Denial of Service in Waitress
Feb 4, 2020
HTTP Request Smuggling: Content-Length Sent Twice in Waitress
Jan 22, 2020
HTTP Request Smuggling in Waitress: Invalid whitespace characters in headers
Dec 26, 2019
HTTP Request Smuggling: LF vs CRLF handling in Waitress
Dec 20, 2019
HTTP Request Smuggling: Invalid Transfer-Encoding in Waitress
Dec 20, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-49768 | Waitress has request processing race condition in HTTP pipelining with invalid first request | CRITICAL | 0.49% | Oct 29, 2024 |
| CVE-2024-49769 | Waitress has a denial of service leading to high CPU usage/resource exhaustion | HIGH | 1.38% | Oct 29, 2024 |
| CVE-2022-31015 | Uncaught Exception (due to a data race) leads to process termination in Waitress | HIGH | 1.47% | May 31, 2022 |
| CVE-2022-24761 | HTTP Request Smuggling in waitress | HIGH | 1.78% | Mar 17, 2022 |
| CVE-2020-5236 | Catastrophic backtracking in regex allows Denial of Service in Waitress | MEDIUM | 2.36% | Feb 4, 2020 |
| CVE-2019-16792 | HTTP Request Smuggling: Content-Length Sent Twice in Waitress | HIGH | 1.98% | Jan 22, 2020 |
| CVE-2019-16789 | HTTP Request Smuggling in Waitress: Invalid whitespace characters in headers | MEDIUM | 2.59% | Dec 26, 2019 |
| CVE-2019-16785 | HTTP Request Smuggling: LF vs CRLF handling in Waitress | MEDIUM | 2.54% | Dec 20, 2019 |
| CVE-2019-16786 | HTTP Request Smuggling: Invalid Transfer-Encoding in Waitress | MEDIUM | 2.38% | Dec 20, 2019 |
Showing 1 to 5 of 5 CVEs