{"id":"CVE-2020-7965","aliases":["GHSA-fjq3-5pxw-4wj4","PYSEC-2020-156"],"url":"https://o3.security/vulnerability/CVE-2020-7965","summary":"Cross-Site Request Forgery in Webargs","details":"flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receiving JSON input. If the request body is valid JSON, it will accept it even if the content type is application/x-www-form-urlencoded. This allows for JSON POST requests to be made across domains, leading to CSRF.","published":"2020-01-29T15:15:11.070Z","modified":"2026-07-08T17:57:02.568865Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"webargs","fixedVersion":"5.5.3"},{"ecosystem":"PyPI","name":"webargs","fixedVersion":"6.0.0b4"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://webargs.readthedocs.io/en/latest/changelog.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T17:57:02.568865Z"}}