{"id":"MGASA-2024-0236","summary":"Updated python-gunicorn packages fix security vulnerability","details":"Gunicorn fails to properly validate Transfer-Encoding headers, leading\nto HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests\nwith conflicting Transfer-Encoding headers, attackers can bypass\nsecurity restrictions and access restricted endpoints. This issue is due\nto Gunicorn's handling of Transfer-Encoding headers, where it\nincorrectly processes requests with multiple, conflicting\nTransfer-Encoding headers, treating them as chunked regardless of the\nfinal encoding specified. This vulnerability allows for a range of\nattacks including cache poisoning, session manipulation, and data\nexposure.\n","modified":"2026-04-16T04:40:47.352774216Z","published":"2024-06-24T19:04:12Z","upstream":["CVE-2024-1135"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2024-0236.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=33146"},{"type":"WEB","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/T3JUAVTE5DCLOJLFBSIK3OPDOUIF7BMB/"}],"affected":[{"package":{"name":"python-gunicorn","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/python-gunicorn?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"22.0.0-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2024-0236.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}