CherryPy is a lightweight, minimalist Python web framework that serves as a foundation for building HTTP servers and web applications, with its vulnerability profile concentrating on the core library itself. The observed weakness classes, centered on path-traversal issues and related input-handling concerns, reflect the framework's role in handling HTTP requests and file-system access patterns. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cherrypy over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0252HIGH Directory traversal vulnerability in the _get_file_path function in (1) lib/sessions.py in CherryPy 3.0.x up to 3.0.2, (2) filter/sessionfilter.py in CherryPy 2.1, and (3) filter/s | Jan 12, 2008 | 7.5 | 20 | NO | NO |
CVE-2006-0847MEDIUM Directory traversal vulnerability in the staticfilter component in CherryPy before 2.1.1 allows remote attackers to read arbitrary files via ".." sequences in unspecified vectors. | Feb 22, 2006 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cherrypy.
Media articles that mention a CVE ID that affects a product developed by Cherrypy — matched by CVE ID, not by vendor name.