Junglewise Threat Intelligence

CVE-2018-1000164: Gunicorn HTTP response header injection via CRLF

CVE-2018-1000164 · Severity: high · CVSS 7.5 · Published 2018-07-12

Technologies: Gunicorn. Vendors: PyPI.

Executive brief

Gunicorn is a widely-used Python application server that handles HTTP requests for web applications. This vulnerability allows remote attackers to inject arbitrary HTTP response headers by embedding CRLF sequences in request data. An attacker could exploit this to set malicious headers, potentially leading to cache poisoning, session fixation, XSS attacks, or other header-based exploits without requiring authentication.

Technical details

The vulnerability is a CRLF injection (CWE-93) in the process_headers function within gunicorn/http/wsgi.py. The vulnerable code fails to neutralize carriage return (\r) and line feed (\n) sequences in HTTP header values, allowing an attacker to inject arbitrary headers by crafting a malicious HTTP request. The attack requires only network access and no authentication or user interaction. An attacker can inject headers to modify response behavior, set cookies, bypass security controls, or perform cache poisoning attacks. The issue was addressed in gunicorn version 19.5.0 and patch commit 1e10a02 in the benoitc/gunicorn repository.

Affected products

  • Gunicorn Gunicorn < 19.5.0

Timeline

  • 2018-07-12: disclosed
  • 2018: patched: Fixed in version 19.5.0

References

Related threats