{"id":"GHSA-v853-p72q-4cfw","summary":"Quart leaks raw request body (incl. plaintext passwords) to stdout via stray debug print in Body.__await__","details":"### Summary\nQuart 0.23.0 contains a stray debug statement (`print(data)`) inside `Body.__await__` in `quart/wrappers/request.py`. Any request whose body is awaited — `await request.form`, `await request.get_data()`, WTForms `validate_on_submit()`, etc. — has its raw, unparsed body printed to stdout, including plaintext form fields such as passwords and CSRF tokens. Confirmed present in 0.23.0, confirmed absent in 0.22.0.\n\n### Details\nIn `src/quart/wrappers/request.py`, `Body.__await__` accumulates the request body into a bytearray:\n\n\u200b```python\ndata = bytearray()\nwhile not self._queue.empty():\n    data.extend(self._queue.get_nowait())\n    print(data)          # \u003c-- not present in 0.22.0\n    if (\n        self._max_content_length is not None\n        and len(data) \u003e self._max_content_length\n    ):\n        raise RequestEntityTooLarge()\n\u200b```\n\nThis fires for every request that awaits its body — the overwhelming majority of POST/PUT routes in a typical Quart app (form submissions, JSON APIs via `request.get_json()`, file uploads, etc.).\n\n### PoC\n1. `pip install quart==0.23.0` (requires Python 3.13+)\n2. Minimal route:\n\u200b```python\n@app.route(\"/login\", methods=[\"POST\"])\nasync def login():\n    form_data = await request.form\n    ...\n\u200b```\n3. Submit a POST with form data, e.g. a login form with `staff_id`/`password` fields.\n4. Observe stdout: the full raw body is printed as `bytearray(b'csrf_token=...&staff_id=...&password=...')`.\n\nConfirmed via source diff against 0.22.0's `request.py`, where this line does not exist.\n\n### Impact\nAny app that captures stdout in logs (terminal redirect, systemd/journald, Docker logs, cloud log aggregation, etc.) will have every submitted form body — including login credentials — written to logs in plaintext. This affects any Quart 0.23.0 app handling authentication or any sensitive form data, and is trivially triggerable by any user simply submitting a form (no attacker action required beyond normal use).","modified":"2026-10-05T23:00:06.312824059Z","published":"2026-10-05T22:49:44Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-10-05T22:49:44Z","nvd_published_at":null,"cwe_ids":["CWE-532"]},"references":[{"type":"WEB","url":"https://github.com/pallets/quart/security/advisories/GHSA-v853-p72q-4cfw"},{"type":"WEB","url":"https://github.com/pallets/quart/commit/e8eb3b8a0cb98e7574bf3841312fc7f96883d055"},{"type":"PACKAGE","url":"https://github.com/pallets/quart"},{"type":"WEB","url":"https://github.com/pallets/quart/releases/tag/0.23.1"}],"affected":[{"package":{"name":"quart","ecosystem":"PyPI","purl":"pkg:pypi/quart"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.23.0"},{"fixed":"0.23.1"}]}],"versions":["0.23.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-v853-p72q-4cfw/GHSA-v853-p72q-4cfw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}