gunicorn
WSGI HTTP Server for UNIX
Activity
- Latest release
- 3w ago
- Total releases
- 99
- Cadence
- ~14 days
- Last 12 months
- 13
Details
- License
- MIT
- First release
- Jan 03, 2010
| Version | Released | |
|---|---|---|
26.2.0
minor
|
26.2.0
minor
Dependencies (13)
+ 5 more |
|
26.1.0
minor
|
26.1.0
minor
Dependencies (13)
+ 5 more |
|
26.0.0
major
|
26.0.0
major
Dependencies (12)
+ 4 more |
|
25.3.0
minor
|
25.3.0
minor
Dependencies (13)
+ 5 more |
|
25.2.0
minor
|
25.2.0
minor
Dependencies (13)
+ 5 more |
|
25.1.0
minor
|
25.1.0
minor
Dependencies (12)
+ 4 more |
|
25.0.3
patch
|
25.0.3
patch
Dependencies (12)
+ 4 more |
|
25.0.2
patch
|
25.0.2
patch
Dependencies (12)
+ 4 more |
|
25.0.1
patch
|
25.0.1
patch
Dependencies (12)
+ 4 more |
|
25.0.0
major
|
25.0.0
major
Dependencies (12)
+ 4 more |
|
24.1.1
patch
|
24.1.1
patch
Dependencies (9)
+ 1 more |
|
24.1.0
minor
|
24.1.0
minor
Dependencies (9)
+ 1 more |
|
24.0.0
major
|
24.0.0
major
Dependencies (9)
+ 1 more |
|
23.0.0
major
|
23.0.0
major
Dependencies (9)
+ 1 more |
|
22.0.0
major
|
22.0.0
major
Dependencies (9)
+ 1 more |
|
21.2.0
minor
2 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
21.2.0
minor
Dependencies (6)
|
|
21.1.0
minor
2 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
21.1.0
minor
Dependencies (6)
|
|
21.0.1
patch
2 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
21.0.1
patch
Dependencies (6)
|
|
21.0.0
major
2 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
21.0.0
major
Dependencies (6)
|
|
20.1.0
minor
2 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
20.1.0
minor
|
|
20.0.4
patch
2 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
20.0.4
patch
Dependencies (5)
|
|
20.0.3
patch
2 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
20.0.3
patch
Dependencies (5)
|
|
20.0.2
patch
2 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
20.0.2
patch
Dependencies (5)
|
|
19.10.0
minor
2 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
19.10.0
minor
Dependencies (3)
|
|
20.0.0
major
2 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
20.0.0
major
Dependencies (5)
|
|
19.9.0
minor
2 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
19.9.0
minor
Dependencies (3)
|
|
19.8.1
patch
2 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
19.8.1
patch
Dependencies (3)
|
|
19.8.0
minor
2 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
19.8.0
minor
Dependencies (3)
|
|
19.7.1
patch
2 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
19.7.1
patch
|
|
19.7.0
minor
2 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
19.7.0
minor
|
|
19.6.0
minor
2 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
19.6.0
minor
|
|
19.5.0
minor
2 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
19.5.0
minor
|
|
19.4.5
patch
3 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2018-1000164
GHSA-32pc-xphx-q4f6
PYSEC-2018-55
Jul 12, 2018
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
High
Network
Low
None
None
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 55 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
Fixed in
19.5.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
19.4.5
patch
|
|
19.4.4
patch
3 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2018-1000164
GHSA-32pc-xphx-q4f6
PYSEC-2018-55
Jul 12, 2018
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
High
Network
Low
None
None
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 55 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
Fixed in
19.5.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
19.4.4
patch
|
|
19.4.3
patch
3 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2018-1000164
GHSA-32pc-xphx-q4f6
PYSEC-2018-55
Jul 12, 2018
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
High
Network
Low
None
None
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 55 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
Fixed in
19.5.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
19.4.3
patch
|
|
19.4.2
patch
3 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2018-1000164
GHSA-32pc-xphx-q4f6
PYSEC-2018-55
Jul 12, 2018
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
High
Network
Low
None
None
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 55 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
Fixed in
19.5.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
19.4.2
patch
|
|
19.4.1
patch
3 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2018-1000164
GHSA-32pc-xphx-q4f6
PYSEC-2018-55
Jul 12, 2018
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
High
Network
Low
None
None
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 55 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
Fixed in
19.5.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
19.4.1
patch
|
|
19.4.0
minor
3 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2018-1000164
GHSA-32pc-xphx-q4f6
PYSEC-2018-55
Jul 12, 2018
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
High
Network
Low
None
None
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 55 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
Fixed in
19.5.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
19.4.0
minor
|
|
19.3.0
minor
3 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2018-1000164
GHSA-32pc-xphx-q4f6
PYSEC-2018-55
Jul 12, 2018
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
High
Network
Low
None
None
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 55 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
Fixed in
19.5.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
19.3.0
minor
|
|
19.2.1
patch
3 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2018-1000164
GHSA-32pc-xphx-q4f6
PYSEC-2018-55
Jul 12, 2018
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
High
Network
Low
None
None
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 55 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
Fixed in
19.5.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
19.2.1
patch
|
|
19.2.0
minor
3 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2018-1000164
GHSA-32pc-xphx-q4f6
PYSEC-2018-55
Jul 12, 2018
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
High
Network
Low
None
None
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 55 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
Fixed in
19.5.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
19.2.0
minor
|
|
19.1.1
patch
3 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2018-1000164
GHSA-32pc-xphx-q4f6
PYSEC-2018-55
Jul 12, 2018
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
High
Network
Low
None
None
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 55 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
Fixed in
19.5.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
19.1.1
patch
|
|
19.1.0
minor
3 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2018-1000164
GHSA-32pc-xphx-q4f6
PYSEC-2018-55
Jul 12, 2018
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
High
Network
Low
None
None
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 55 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
Fixed in
19.5.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
19.1.0
minor
|
|
19.0.0
major
3 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2018-1000164
GHSA-32pc-xphx-q4f6
PYSEC-2018-55
Jul 12, 2018
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
High
Network
Low
None
None
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 55 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
Fixed in
19.5.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
19.0.0
major
|
|
18.0
major
3 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2018-1000164
GHSA-32pc-xphx-q4f6
PYSEC-2018-55
Jul 12, 2018
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
High
Network
Low
None
None
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 55 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
Fixed in
19.5.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
18.0
major
|
|
17.5
major
3 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2018-1000164
GHSA-32pc-xphx-q4f6
PYSEC-2018-55
Jul 12, 2018
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
High
Network
Low
None
None
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 55 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
Fixed in
19.5.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
17.5
major
|
|
0.17.4
patch
3 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2018-1000164
GHSA-32pc-xphx-q4f6
PYSEC-2018-55
Jul 12, 2018
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
High
Network
Low
None
None
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 55 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
Fixed in
19.5.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
0.17.4
patch
|
|
0.17.3
patch
3 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2018-1000164
GHSA-32pc-xphx-q4f6
PYSEC-2018-55
Jul 12, 2018
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
High
Network
Low
None
None
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 55 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
Fixed in
19.5.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
0.17.3
patch
|
|
0.17.2
patch
3 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2018-1000164
GHSA-32pc-xphx-q4f6
PYSEC-2018-55
Jul 12, 2018
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
High
Network
Low
None
None
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 55 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
Fixed in
19.5.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
0.17.2
patch
|
|
0.17.1
patch
3 CVEs
CVE-2024-6827
PYSEC-2026-1433
GHSA-hc5x-x2vx-497g
Jul 07, 2026
Gunicorn HTTP Request/Response Smuggling vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-1135
PYSEC-2026-1434
GHSA-w3h3-4rj7-4ph4
Jul 07, 2026
Request smuggling leading to endpoint restriction bypass in Gunicorn
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability has been shown to allow access to endpoints restricted by gunicorn. This issue has been addressed in version 22.0.0. To be affected users must have a network path which does not filter out invalid requests. These users are advised to block access to restricted endpoints via a firewall or other mechanism if they are unable to update. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 73 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.10.0
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
19.5.0
19.6.0
19.7.0
19.7.1
19.8.0
19.8.1
19.9.0
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.1.0
21.0.0
21.0.1
21.1.0
21.2.0
Fixed in
22.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2018-1000164
GHSA-32pc-xphx-q4f6
PYSEC-2018-55
Jul 12, 2018
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
High
Network
Low
None
None
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0. Affected versions
0.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
0.12.2
0.13.0
0.13.1
0.13.2
+ 55 more Show less
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.2
0.2.1
0.3
0.3.1
0.3.2
0.4
0.4.1
0.4.2
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
17.5
18.0
19.0.0
19.1.0
19.1.1
19.2.0
19.2.1
19.3.0
19.4.0
19.4.1
19.4.2
19.4.3
19.4.4
19.4.5
Fixed in
19.5.0
References
Updated Sep 08, 2026 · Source: OSV.dev |
0.17.1
patch
|