{"id":"CVE-2014-3137","aliases":["GHSA-873q-wpqr-xfgw","PYSEC-2014-77"],"url":"https://o3.security/vulnerability/CVE-2014-3137","summary":"Bottle does not properly limit content-types","details":"Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restrictions via an accepted Content-Type followed by a ; (semi-colon) and a Content-Type that would not be accepted, as demonstrated in YouCompleteMe to execute arbitrary code.","published":"2014-10-25T22:55:04Z","modified":"2026-04-10T03:44:38.578978Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"bottle","fixedVersion":"0.10.12"},{"ecosystem":"PyPI","name":"bottle","fixedVersion":"0.11.7"},{"ecosystem":"PyPI","name":"bottle","fixedVersion":"0.12.6"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://www.debian.org/security/2014/dsa-2948"},{"type":"ADVISORY","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1093255"},{"type":"REPORT","url":"https://github.com/defnull/bottle/issues/616"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2014/05/01/15"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-3137"},{"type":"WEB","url":"https://github.com/bottlepy/bottle/issues/616"},{"type":"PACKAGE","url":"https://github.com/bottlepy/bottle"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/bottle/PYSEC-2014-77.yaml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-10T03:44:38.578978Z"}}