Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-31015

17
FAUCET Score

CVE-2022-31015 affects Waitress versions 2.1.0 and 2.1.1, a Web Server Gateway Interface server for Python, where a race condition can cause the application to terminate unexpectedly. This medium-severity vulnerability (CVSS 5.9) has a network attack vector and high attack complexity, leading to high availability impact (denial of service) without affecting confidentiality or integrity. There is no known active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.1.0, < 2.1.2CPE matchmatch criteria
cpe:2.3:a:agendaless:waitress:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.43%
Probability of exploitation in next 30 days
EPSS Percentile
70.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0143 is in the 42nd percentile among its peer group of 19,956 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: 17597-17084Fixed in: 3.0.1-1
microsoftpatch availablevia msrc
Product: azl3 python-waitress 3.0.1-1 on Azure Linux 3.0Fixed in: 3.0.1-1
pippatch availablevia ghsa
Product: waitressFixed in: 2.1.2

Vendor Advisories (3)

pipGHSA-f5x9-8jwc-25rwhigh

Uncaught Exception (due to a data race) leads to process termination in Waitress

Jun 2, 2022
redhatCVE-2022-31015Low

waitress: uncaught Exception (due to a data race) leads to process termination

Jun 1, 2022
microsoft2022-May/CVE-2022-31015Moderate

Uncaught Exception (due to a data race) leads to process termination in Waitress

May 10, 2022

References

github.com / Pylons/waitress/commit/4f6789b035610e0552738cdc4b35ca809a592d48
PatchThird Party Advisory
github.com / Pylons/waitress/issues/374
ExploitIssue TrackingPatchThird Party Advisory
github.com / Pylons/waitress/pull/377
Issue TrackingPatchThird Party Advisory
github.com / Pylons/waitress/security/advisories/GHSA-f5x9-8jwc-25rw
Third Party Advisory