OESA-2026-3658
Dashboard / Vulnerabilities / OESA-2026-3658
Summary: python-gunicorn security update
Details: Gunicorn(Green Unicorn) is a Python WSGI HTTP Server for UNIX. It's a pre-fork worker model ported from Ruby's Unicorn_ project. The Gunicorn server is broadly compatible with various web frameworks, simply implemented, light on server resource usage, and fairly speedy. Security Fix(es): Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability allows for a range of attacks including cache poisoning, session manipulation, and data exposure.(CVE-2024-1135)
References: https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3658, https://nvd.nist.gov/vuln/detail/CVE-2024-1135
Affected packages
Package
Name: python-gunicorn
Purl: pkg:rpm/openEuler/python-gunicorn&distro=openEuler-24.03-LTS-SP4
Affected ranges
Type: ECOSYSTEM
Events:
