Related Vulnerabilities: CVE-2022-24761  

waitress behind a proxy that does not properly validate the incoming HTTP request matches the RFC7230 is vulnerable to request smuggling due to a disagreement between waitress and the proxy on where one request starts and where it ends.

Severity High

Remote Yes

Type Unknown

Description

waitress behind a proxy that does not properly validate the incoming HTTP request matches the RFC7230 is vulnerable to request smuggling due to a disagreement between waitress and the proxy on where one request starts and where it ends.

AVG-2723 python-waitress 2.1.0-1 2.1.1-1 High Fixed

https://github.com/Pylons/waitress/commit/9e0b8c801e4d505c2ffc91b891af4ba48af715e0
https://github.com/Pylons/waitress/security/advisories/GHSA-4f7p-27jc-3c36
https://github.com/Pylons/waitress/releases/tag/v2.1.1