VDB
Sign up
—

PYSEC-2022-203

Quick fix

PYSEC-2022-203 — werkzeug: upgrade to the fixed version with the command below.

pip install --upgrade 'werkzeug>=9a3a981d70d2e9ec3344b5192f86fcaf3210cd85'

Details

** DISPUTED ** Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inside the body. NOTE: the vendor's position is that this behavior can only occur in unsupported configurations involving development mode and an HTTP server from outside the Werkzeug project.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/werkzeug
Introduced in: 0Fixed in: 9a3a981d70d2e9ec3344b5192f86fcaf3210cd85
Fixpip install --upgrade 'werkzeug>=9a3a981d70d2e9ec3344b5192f86fcaf3210cd85'

References