Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-24761

26
FAUCET Score

CVE-2022-24761 is a request smuggling vulnerability affecting Waitress versions 2.1.0 and prior, a Web Server Gateway Interface server for Python. When Waitress is deployed behind a proxy that does not strictly validate HTTP requests against RFC7230, an attacker can manipulate requests, leading to disagreement between the proxy and Waitress on request boundaries. This allows for request smuggling, potentially bypassing security controls. The vulnerability has a CVSS score of 7.5 (High), indicating it can be exploited remotely with low attack complexity, requiring no user interaction, and can lead to high integrity impact. The root cause involves Waitress's parsing of integer strings and its handling of chunk extensions. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or Nuclei. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness or active threat intelligence.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.1.1CPE matchmatch criteria
cpe:2.3:a:agendaless:waitress:*:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.78%
Probability of exploitation in next 30 days
EPSS Percentile
75.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0178 is in the 59th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: azl3 python-waitress 3.0.1-1 on Azure Linux 3.0Fixed in: 3.0.1-1
microsoftpatch availablevia msrc
Product: 17597-17084Fixed in: 3.0.1-1
pippatch availablevia ghsa
Product: waitressFixed in: 2.1.1
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 16.1Fixed in: python-waitress-0:2.0.0-1.el8ost
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 16.2Fixed in: python-waitress-0:2.0.0-1.el8ost
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 13.0 - ELSFixed in: python-waitress-0:1.4.4-2.el7ost
View patch
redhatno patchvia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel8

Vendor Advisories (3)

pipGHSA-4f7p-27jc-3c36high

HTTP Request Smuggling in waitress

Mar 18, 2022
redhatCVE-2022-24761Important

waitress: Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')

Mar 17, 2022
microsoft2022-Mar/CVE-2022-24761Important

HTTP Request Smuggling in waitress

Mar 8, 2022

References

github.com / Pylons/waitress/commit/9e0b8c801e4d505c2ffc91b891af4ba48af715e0
PatchRelease NotesThird Party Advisory
github.com / Pylons/waitress/releases/tag/v2.1.1
Release NotesThird Party Advisory
github.com / Pylons/waitress/security/advisories/GHSA-4f7p-27jc-3c36
Third Party Advisory
lists.debian.org / debian-lts-announce/2022/05/msg00011.html
Mailing ListThird Party Advisory
debian.org / security/2022/dsa-5138
Third Party Advisory