CVE-2020-7695
Published Jul 27, 2020Uvicorn before 0.11.7 is vulnerable to HTTP response splitting. CRLF sequences are not escaped in the value of HTTP headers. Attackers can exploit this to add arbitrary headers to…
Vendor/product archive
2 CVEs tagged to encode / uvicorn — 0 Critical, 0 High, 1 Medium, 1 Low, 0 Unrated.
Uvicorn before 0.11.7 is vulnerable to HTTP response splitting. CRLF sequences are not escaped in the value of HTTP headers. Attackers can exploit this to add arbitrary headers to…
This affects all versions of package uvicorn. The request logger provided by the package is vulnerable to ASNI escape sequence injection. Whenever any HTTP request is received, th…