{"schema_version":1,"title":"waitress (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 14 vulnerabilities in waitress (PyPI): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2024-49769, was published on 29 October 2024.","url":"https://junglewise.ai/threats/technologies/waitress","json_url":"https://junglewise.ai/threats/technologies/waitress.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/waitress","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":14,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":0},"latest":[{"cve":"CVE-2024-49769","cvss":3.1,"epss":0.0138,"slug":"cve-2024-49769-waitress-denial-of-service-via-unclean-socket-handling","title":"PYSEC-2024-211 - Waitress is a Web Server Gateway Interface server for Python 2 and 3. When a remote client closes the connection before waitress has had the","severity":"low","exploited":false,"published_at":"2024-10-29T15:15:12+00:00","url":"https://junglewise.ai/threats/cve-2024-49769-waitress-denial-of-service-via-unclean-socket-handling"},{"cve":"CVE-2024-49768","cvss":3.1,"epss":0.0049,"slug":"cve-2024-49768-waitress-has-request-processing-race-condition-in-http-pipelining","title":"PYSEC-2024-210 - Waitress is a Web Server Gateway Interface server for Python 2 and 3. A remote client may send a request that is exactly recv_bytes (default","severity":"low","exploited":false,"published_at":"2024-10-29T15:15:11+00:00","url":"https://junglewise.ai/threats/cve-2024-49768-waitress-has-request-processing-race-condition-in-http-pipelining"},{"cve":"CVE-2022-31015","cvss":3.1,"epss":0.0147,"slug":"cve-2022-31015-uncaught-exception-due-to-a-data-race-leads-to-process","title":"PYSEC-2022-205 - Waitress is a Web Server Gateway Interface server for Python 2 and 3. Waitress versions 2.1.0 and 2.1.1 may terminate early due to a thread","severity":"low","exploited":false,"published_at":"2022-05-31T23:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-31015-uncaught-exception-due-to-a-data-race-leads-to-process"},{"cve":"CVE-2022-24761","cvss":3.1,"epss":0.0178,"slug":"cve-2022-24761-http-request-smuggling-in-waitress","title":"PYSEC-2022-169 - Waitress is a Web Server Gateway Interface server for Python 2 and 3. When using Waitress versions 2.1.0 and prior behind a proxy that does","severity":"low","exploited":false,"published_at":"2022-03-17T13:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-24761-http-request-smuggling-in-waitress"},{"cve":"CVE-2020-5236","cvss":3.1,"epss":0.0236,"slug":"cve-2020-5236-catastrophic-backtracking-in-regex-allows-denial-of-service-in","title":"PYSEC-2020-155 - Waitress version 1.4.2 allows a DOS attack When waitress receives a header that contains invalid characters. When a header like \"Bad-header","severity":"low","exploited":false,"published_at":"2020-02-04T03:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-5236-catastrophic-backtracking-in-regex-allows-denial-of-service-in"},{"slug":"pysec-2020-197-waitress-through-version-1-3-1-allows-request-smuggling-9f6e1628","title":"PYSEC-2020-197 - Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would header fold a double Cont","severity":"info","exploited":false,"published_at":"2020-01-22T19:15:00+00:00","url":"https://junglewise.ai/threats/pysec-2020-197-waitress-through-version-1-3-1-allows-request-smuggling-9f6e1628"},{"cve":"CVE-2019-16792","cvss":3.1,"epss":0.0198,"slug":"cve-2019-16792-http-request-smuggling-content-length-sent-twice-in-waitress","title":"PYSEC-2020-178 - Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would header fold a double Cont","severity":"low","exploited":false,"published_at":"2020-01-22T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2019-16792-http-request-smuggling-content-length-sent-twice-in-waitress"},{"cve":"CVE-2019-16789","cvss":3.1,"epss":0.0259,"slug":"cve-2019-16789-http-request-smuggling-in-waitress-invalid-whitespace-characters","title":"PYSEC-2019-138 - In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypass","severity":"low","exploited":false,"published_at":"2019-12-26T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2019-16789-http-request-smuggling-in-waitress-invalid-whitespace-characters"},{"slug":"pysec-2019-68-in-waitress-through-version-1-4-0-if-a-proxy-server-is-4705649e","title":"PYSEC-2019-68 - In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypass","severity":"info","exploited":false,"published_at":"2019-12-26T17:15:00+00:00","url":"https://junglewise.ai/threats/pysec-2019-68-in-waitress-through-version-1-4-0-if-a-proxy-server-is-4705649e"},{"slug":"http-request-smuggling-invalid-whitespace-characters-in-headers-in-6de21fce","title":"HTTP Request Smuggling: Invalid whitespace characters in headers in Waitress","severity":"info","exploited":false,"published_at":"2019-12-26T16:34:38+00:00","url":"https://junglewise.ai/threats/http-request-smuggling-invalid-whitespace-characters-in-headers-in-6de21fce"},{"slug":"pysec-2019-66-waitress-through-version-1-3-1-implemented-a-may-part-of-f0ddf309","title":"PYSEC-2019-66 - Waitress through version 1.3.1 implemented a \"MAY\" part of the RFC7230 which states: \"Although the line terminator for the start-line and he","severity":"info","exploited":false,"published_at":"2019-12-20T23:15:00+00:00","url":"https://junglewise.ai/threats/pysec-2019-66-waitress-through-version-1-3-1-implemented-a-may-part-of-f0ddf309"},{"cve":"CVE-2019-16786","cvss":3.1,"epss":0.0238,"slug":"cve-2019-16786-http-request-smuggling-invalid-transfer-encoding-in-waitress","title":"PYSEC-2019-137 - Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunk","severity":"low","exploited":false,"published_at":"2019-12-20T23:15:00+00:00","url":"https://junglewise.ai/threats/cve-2019-16786-http-request-smuggling-invalid-transfer-encoding-in-waitress"},{"slug":"pysec-2019-67-waitress-through-version-1-3-1-would-parse-the-transfer-95cbf730","title":"PYSEC-2019-67 - Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunk","severity":"info","exploited":false,"published_at":"2019-12-20T23:15:00+00:00","url":"https://junglewise.ai/threats/pysec-2019-67-waitress-through-version-1-3-1-would-parse-the-transfer-95cbf730"},{"cve":"CVE-2019-16785","cvss":3.1,"epss":0.0254,"slug":"cve-2019-16785-http-request-smuggling-lf-vs-crlf-handling-in-waitress","title":"PYSEC-2019-136 - Waitress through version 1.3.1 implemented a \"MAY\" part of the RFC7230 which states: \"Although the line terminator for the start-line and he","severity":"low","exploited":false,"published_at":"2019-12-20T23:15:00+00:00","url":"https://junglewise.ai/threats/cve-2019-16785-http-request-smuggling-lf-vs-crlf-handling-in-waitress"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"waitress (PyPI)","slug":"waitress","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"description":"Waitress is a pure-Python WSGI web application server.","url":"https://junglewise.ai/threats/technologies/waitress"},"most_severe":[{"cve":"CVE-2019-16789","cvss":3.1,"epss":0.0259,"slug":"cve-2019-16789-http-request-smuggling-in-waitress-invalid-whitespace-characters","title":"PYSEC-2019-138 - In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypass","severity":"low","exploited":false,"published_at":"2019-12-26T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2019-16789-http-request-smuggling-in-waitress-invalid-whitespace-characters"},{"cve":"CVE-2019-16785","cvss":3.1,"epss":0.0254,"slug":"cve-2019-16785-http-request-smuggling-lf-vs-crlf-handling-in-waitress","title":"PYSEC-2019-136 - Waitress through version 1.3.1 implemented a \"MAY\" part of the RFC7230 which states: \"Although the line terminator for the start-line and he","severity":"low","exploited":false,"published_at":"2019-12-20T23:15:00+00:00","url":"https://junglewise.ai/threats/cve-2019-16785-http-request-smuggling-lf-vs-crlf-handling-in-waitress"},{"cve":"CVE-2019-16786","cvss":3.1,"epss":0.0238,"slug":"cve-2019-16786-http-request-smuggling-invalid-transfer-encoding-in-waitress","title":"PYSEC-2019-137 - Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunk","severity":"low","exploited":false,"published_at":"2019-12-20T23:15:00+00:00","url":"https://junglewise.ai/threats/cve-2019-16786-http-request-smuggling-invalid-transfer-encoding-in-waitress"},{"cve":"CVE-2020-5236","cvss":3.1,"epss":0.0236,"slug":"cve-2020-5236-catastrophic-backtracking-in-regex-allows-denial-of-service-in","title":"PYSEC-2020-155 - Waitress version 1.4.2 allows a DOS attack When waitress receives a header that contains invalid characters. When a header like \"Bad-header","severity":"low","exploited":false,"published_at":"2020-02-04T03:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-5236-catastrophic-backtracking-in-regex-allows-denial-of-service-in"},{"cve":"CVE-2019-16792","cvss":3.1,"epss":0.0198,"slug":"cve-2019-16792-http-request-smuggling-content-length-sent-twice-in-waitress","title":"PYSEC-2020-178 - Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would header fold a double Cont","severity":"low","exploited":false,"published_at":"2020-01-22T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2019-16792-http-request-smuggling-content-length-sent-twice-in-waitress"},{"cve":"CVE-2022-24761","cvss":3.1,"epss":0.0178,"slug":"cve-2022-24761-http-request-smuggling-in-waitress","title":"PYSEC-2022-169 - Waitress is a Web Server Gateway Interface server for Python 2 and 3. When using Waitress versions 2.1.0 and prior behind a proxy that does","severity":"low","exploited":false,"published_at":"2022-03-17T13:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-24761-http-request-smuggling-in-waitress"},{"cve":"CVE-2022-31015","cvss":3.1,"epss":0.0147,"slug":"cve-2022-31015-uncaught-exception-due-to-a-data-race-leads-to-process","title":"PYSEC-2022-205 - Waitress is a Web Server Gateway Interface server for Python 2 and 3. Waitress versions 2.1.0 and 2.1.1 may terminate early due to a thread","severity":"low","exploited":false,"published_at":"2022-05-31T23:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-31015-uncaught-exception-due-to-a-data-race-leads-to-process"},{"cve":"CVE-2024-49769","cvss":3.1,"epss":0.0138,"slug":"cve-2024-49769-waitress-denial-of-service-via-unclean-socket-handling","title":"PYSEC-2024-211 - Waitress is a Web Server Gateway Interface server for Python 2 and 3. When a remote client closes the connection before waitress has had the","severity":"low","exploited":false,"published_at":"2024-10-29T15:15:12+00:00","url":"https://junglewise.ai/threats/cve-2024-49769-waitress-denial-of-service-via-unclean-socket-handling"},{"cve":"CVE-2024-49768","cvss":3.1,"epss":0.0049,"slug":"cve-2024-49768-waitress-has-request-processing-race-condition-in-http-pipelining","title":"PYSEC-2024-210 - Waitress is a Web Server Gateway Interface server for Python 2 and 3. A remote client may send a request that is exactly recv_bytes (default","severity":"low","exploited":false,"published_at":"2024-10-29T15:15:11+00:00","url":"https://junglewise.ai/threats/cve-2024-49768-waitress-has-request-processing-race-condition-in-http-pipelining"},{"slug":"pysec-2020-197-waitress-through-version-1-3-1-allows-request-smuggling-9f6e1628","title":"PYSEC-2020-197 - Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would header fold a double Cont","severity":"info","exploited":false,"published_at":"2020-01-22T19:15:00+00:00","url":"https://junglewise.ai/threats/pysec-2020-197-waitress-through-version-1-3-1-allows-request-smuggling-9f6e1628"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}