PT-2024-30667 · Send+1 · Send+1

Adamkorcz

·

Published

2024-09-10

·

Updated

2025-06-23

·

CVE-2024-43799

CVSS v3.1

5.0

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Send versions prior to 0.19.0
Description The issue arises from passing untrusted user input to SendStream.redirect(), which can execute untrusted code. This occurs even when the input is sanitized. The library Send is used for streaming files from the file system as an HTTP response.
Recommendations For versions prior to 0.19.0, update to version 0.19.0 to patch the issue. As a temporary workaround, ensure any untrusted inputs are safe by validating them against an explicit allowlist.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

AZL-49088
AZL-49123
AZL-49164
CVE-2024-43799
DLA-4224-1
GHSA-M6FV-JMCG-4JFG

Affected Products

Debian
Send