VDB
Sign up
HIGH7.5

PYSEC-2026-1058

Apache HTTP Server via mod_proxy_uwsgi HTTP response smuggling

Quick fix

PYSEC-2026-1058 — uwsgi: upgrade to the fixed version with the command below.

pip install --upgrade 'uwsgi>=2.0.22'

Details

HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server from 2.4.30 through 2.4.55 and the uWSGI PyPI package prior to version 2.0.22. Special characters in the origin response header can truncate/split the response forwarded to the client.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/uwsgi
Introduced in: 0Fixed in: 2.0.22
Fixpip install --upgrade 'uwsgi>=2.0.22'

References