VDB
Sign up
—

PYSEC-2020-239

Quick fix

PYSEC-2020-239 — meinheld: upgrade to the fixed version with the command below.

pip install --upgrade 'meinheld>=1.0.2'

Details

meinheld prior to 1.0.2 is vulnerable to HTTP Request Smuggling. HTTP pipelining issues and request smuggling attacks might be possible due to incorrect Content-Length and Transfer encoding header parsing.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/meinheld
Introduced in: 0Fixed in: 1.0.2
Fixpip install --upgrade 'meinheld>=1.0.2'

References