Skip to main content

Vendor/product archive

encode / uvicorn CVEs

Beta · best-effort

2 CVEs tagged to encode / uvicorn0 Critical, 0 High, 1 Medium, 1 Low, 0 Unrated.

CVE-2020-7695

Published Jul 27, 2020

Uvicorn before 0.11.7 is vulnerable to HTTP response splitting. CRLF sequences are not escaped in the value of HTTP headers. Attackers can exploit this to add arbitrary headers to…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7694

Published Jul 27, 2020

This affects all versions of package uvicorn. The request logger provided by the package is vulnerable to ASNI escape sequence injection. Whenever any HTTP request is received, th…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1