Description
** DISPUTED ** Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inside the body. NOTE: the vendor's position is that this behavior can only occur in unsupported configurations involving development mode and an HTTP server from outside the Werkzeug project.
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| werkzeug | — | 2.1.1 |
References
Similar Threats
- High ROOT-APP-PYPI-CVE-2023-25577
- Medium ROOT-APP-PYPI-CVE-2023-46136
- High ROOT-APP-PYPI-CVE-2024-34069
- Medium ROOT-APP-PYPI-CVE-2024-49766
- Medium ROOT-APP-PYPI-CVE-2024-49767
Exploit Protection
Help block exploit attempts
BotEraser is designed to detect and help reduce malicious bot traffic that may target known vulnerabilities on your site.
Try BotEraser Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.