{"id":"CVE-2018-1000164","aliases":["GHSA-32pc-xphx-q4f6","PYSEC-2018-55"],"url":"https://o3.security/vulnerability/CVE-2018-1000164","summary":"Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers","details":"gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in \"process_headers\" function in \"gunicorn/http/wsgi.py\" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0.","published":"2018-04-18T19:29:00.707Z","modified":"2026-07-08T05:50:11.644600145Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":{"score":0.02452,"percentile":0.82812,"asOf":"2026-08-05"},"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"PyPI","name":"gunicorn","fixedVersion":"19.5.0"}],"fix":null,"references":[{"type":"WEB","url":"https://usn.ubuntu.com/4022-1/"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2018/04/msg00022.html"},{"type":"ADVISORY","url":"https://www.debian.org/security/2018/dsa-4186"},{"type":"REPORT","url":"https://github.com/benoitc/gunicorn/issues/1227"},{"type":"EVIDENCE","url":"https://epadillas.github.io/2018/04/02/http-header-splitting-in-gunicorn-19.4.5"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:50:11.644600145Z"}}