threat
engine
.sh
Back
·
··:··
Home
/
Product
/
agendaless waitress
Product
agendaless waitress
9 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2024-49769
< 3.0.1
Waitress is a Web Server Gateway Interface server for Python 2 and 3. When a remote client closes the connection before waitress h
7.5
HIGH
CVE-2024-49768
>= 2.0.0 and < 3.0.1
Waitress is a Web Server Gateway Interface server for Python 2 and 3. A remote client may send a request that is exactly recv_byte
9.1
CRITICAL
CVE-2022-31015
>= 2.1.0 and < 2.1.2
Waitress is a Web Server Gateway Interface server for Python 2 and 3. Waitress versions 2.1.0 and 2.1.1 may terminate early due to
6.5
MEDIUM
CVE-2022-24761
< 2.1.1
Waitress is a Web Server Gateway Interface server for Python 2 and 3. When using Waitress versions 2.1.0 and prior behind a proxy
7.5
HIGH
CVE-2020-5236
all versions
Waitress version 1.4.2 allows a DOS attack When waitress receives a header that contains invalid characters. When a header like "B
5.7
MEDIUM
CVE-2019-16792
<= 1.3.1
Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would header fold a d
7.1
HIGH
CVE-2019-16789
<= 1.4.0
In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker t
7.1
HIGH
CVE-2019-16786
< 1.3.1
Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was
7.1
HIGH
CVE-2019-16785
<= 1.3.1
Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the start-l
7.1
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin