Back to bug 1831068

Who When What Removed Added
Guilherme de Almeida Suckevicz 2020-05-04 14:56:32 UTC Blocks 1831070
Jason Shepherd 2020-05-05 22:40:27 UTC Doc Text The regex used to parse HTTP Headers in python-waitress is vulnerable to catastrophic backtracking. An attacker able to send HTTP requests to a vulnerable server could cause a Denial of Service attack.
RaTasha Tillery-Smith 2020-05-06 12:57:02 UTC Doc Text The regex used to parse HTTP Headers in python-waitress is vulnerable to catastrophic backtracking. An attacker able to send HTTP requests to a vulnerable server could cause a Denial of Service attack. A flaw was found in the regex used to process HTTP Headers in python-waitress and is vulnerable to catastrophic backtracking. This flaw allows an attacker with the ability to send HTTP requests to a vulnerable server to cause a denial of service attack.
Summer Long 2020-05-07 03:34:23 UTC Fixed In Version waitress 1.4.3
Summer Long 2020-05-07 04:12:46 UTC Depends On 1832677, 1832676
PnT Account Manager 2020-07-10 21:43:12 UTC CC kbasil
PnT Account Manager 2020-08-21 21:32:45 UTC CC jschorr
Red Hat Bugzilla 2021-06-22 00:26:32 UTC CC dbecker
Red Hat Bugzilla 2022-01-08 05:28:38 UTC CC jokerman
Red Hat Bugzilla 2023-07-07 08:29:31 UTC Assignee security-response-team nobody

Back to bug 1831068