Technology · PyPI
waitress (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 14 vulnerabilities in waitress (PyPI): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2024-49769, was published on 29 October 2024.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
Latest waitress (PyPI) vulnerabilities
- CVE-2024-49769: PYSEC-2024-211 - Waitress is a Web Server Gateway Interface server for Python 2 and 3. When a remote client closes the…lowCVSS 3.1EPSS 1.4%
- CVE-2024-49768: PYSEC-2024-210 - Waitress is a Web Server Gateway Interface server for Python 2 and 3. A remote client may send a request…lowCVSS 3.1EPSS 0.5%
- CVE-2022-31015: PYSEC-2022-205 - Waitress is a Web Server Gateway Interface server for Python 2 and 3. Waitress versions 2.1.0 and 2.1.1…lowCVSS 3.1EPSS 1.5%
- CVE-2022-24761: PYSEC-2022-169 - Waitress is a Web Server Gateway Interface server for Python 2 and 3. When using Waitress versions 2.1.0…lowCVSS 3.1EPSS 1.8%
- CVE-2020-5236: PYSEC-2020-155 - Waitress version 1.4.2 allows a DOS attack When waitress receives a header that contains invalid…lowCVSS 3.1EPSS 2.4%
- PYSEC-2020-197 - Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would header…info
- CVE-2019-16792: PYSEC-2020-178 - Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice…lowCVSS 3.1EPSS 2.0%
- CVE-2019-16789: PYSEC-2019-138 - In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may…lowCVSS 3.1EPSS 2.6%
- PYSEC-2019-68 - In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an…info
- HTTP Request Smuggling: Invalid whitespace characters in headers in Waitressinfo
- PYSEC-2019-66 - Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the…info
- CVE-2019-16786: PYSEC-2019-137 - Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string…lowCVSS 3.1EPSS 2.4%
- PYSEC-2019-67 - Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that…info
- CVE-2019-16785: PYSEC-2019-136 - Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line…lowCVSS 3.1EPSS 2.5%
Most severe waitress (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2019-16789: PYSEC-2019-138 - In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may…lowCVSS 3.1EPSS 2.6%
- CVE-2019-16785: PYSEC-2019-136 - Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line…lowCVSS 3.1EPSS 2.5%
- CVE-2019-16786: PYSEC-2019-137 - Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string…lowCVSS 3.1EPSS 2.4%
- CVE-2020-5236: PYSEC-2020-155 - Waitress version 1.4.2 allows a DOS attack When waitress receives a header that contains invalid…lowCVSS 3.1EPSS 2.4%
- CVE-2019-16792: PYSEC-2020-178 - Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice…lowCVSS 3.1EPSS 2.0%
- CVE-2022-24761: PYSEC-2022-169 - Waitress is a Web Server Gateway Interface server for Python 2 and 3. When using Waitress versions 2.1.0…lowCVSS 3.1EPSS 1.8%
- CVE-2022-31015: PYSEC-2022-205 - Waitress is a Web Server Gateway Interface server for Python 2 and 3. Waitress versions 2.1.0 and 2.1.1…lowCVSS 3.1EPSS 1.5%
- CVE-2024-49769: PYSEC-2024-211 - Waitress is a Web Server Gateway Interface server for Python 2 and 3. When a remote client closes the…lowCVSS 3.1EPSS 1.4%
- CVE-2024-49768: PYSEC-2024-210 - Waitress is a Web Server Gateway Interface server for Python 2 and 3. A remote client may send a request…lowCVSS 3.1EPSS 0.5%
- PYSEC-2020-197 - Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would header…info
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/waitress.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "waitress (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/waitress, 26 September 2026.