PT-2022-5090 · Pallets+1 · Werkzeug+1

Acipmo

·

Published

2022-02-17

·

Updated

2025-04-11

·

CVE-2022-29361

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Pallets Werkzeug versions 2.1.0 and below
Description The issue is related to improper parsing of HTTP requests, which can allow an attacker to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inside the body. This can occur in unsupported configurations involving development mode and an HTTP server from outside the Werkzeug project. The vendor's position is that this behavior is only possible under specific conditions.
Recommendations For versions 2.1.0 and below, consider disabling development mode and using an HTTP server within the Werkzeug project to minimize the risk of exploitation. Restrict access to the HTTP request parsing functionality until a patch is available. Avoid using crafted HTTP requests with multiple requests included inside the body in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2662
ALT-PU-2025-3304
BDU:2022-06319
CVE-2022-29361
OPENSUSE-SU-2024:13098-1
PYSEC-2022-203

Affected Products

Alt Linux
Werkzeug