VDB
Sign up
—

PYSEC-2026-761

Zope Server vulnerable to DoS via header injection

Quick fix

PYSEC-2026-761 — zope: upgrade to the fixed version with the command below.

pip install --upgrade 'zope>=2.4.4b2'

Details

Zope is a Web application server for Linux. Zope versions 2.0 through 2.5.1 b1 are vulnerable to a denial of service attack, caused by a vulnerability that occurs when using the "through the Web code" capability. A remote attacker could inject malicious headers into a response to cause the vulnerable system to crash.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/zope
Introduced in: 2.0.0Fixed in: 2.4.4b2
Fixpip install --upgrade 'zope>=2.4.4b2'

References