VDB
KO
HIGH 7.5

GHSA-vcph-37mh-fqrh

Apache HTTP Server via mod_proxy_uwsgi HTTP response smuggling

Details

HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server from 2.4.30 through 2.4.55 and the uWSGI PyPI package prior to version 2.0.22. Special characters in the origin response header can truncate/split the response forwarded to the client.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / uwsgi
Introduced in: 0 Fixed in: 2.0.22
Fix pip install --upgrade 'uwsgi>=2.0.22'

References