Bottle is a lightweight Python web framework whose vulnerability profile centers on HTTP parsing and request-handling logic in its single core product. The recurring weakness classes—improper handling of exceptional conditions, input validation gaps, CRLF injection, and HTTP request smuggling—reflect the complexity of correctly parsing and neutralizing untrusted HTTP traffic in a compact framework implementation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bottlepy over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-31799CRITICAL Bottle before 0.12.20 mishandles errors during early request binding. | Jun 2, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-28473MEDIUM The package bottle from 0 and before 0.12.19 are vulnerable to Web Cache Poisoning by using a vector called parameter cloaking. When the attacker can separate query parameters usin | Jan 18, 2021 | 6.8 | 23 | NO | NO |
CVE-2014-3137MEDIUM Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restrict | Oct 25, 2014 | 6.8 | 19 | NO | NO |
CVE-2016-9964MEDIUM redirect() in bottle.py in bottle 0.12.10 doesn't filter a "\r\n" sequence, which leads to a CRLF attack, as demonstrated by a redirect("233\r\nSet-Cookie: name=salt") call. | Dec 16, 2016 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bottlepy.
Media articles that mention a CVE ID that affects a product developed by Bottlepy — matched by CVE ID, not by vendor name.