Modwsgi is an Apache module that bridges Python applications to the web server, presenting a narrow but strategically positioned attack surface in application-server integration layers. Its observed vulnerability patterns center on information disclosure, data-authenticity failures, and trust-boundary issues, reflecting the sensitivities inherent to credential and session handling between the web tier and application runtime. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Modwsgi over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-0242HIGH mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from | Dec 9, 2019 | 7.5 | 32 | NO | YES |
CVE-2022-2255HIGH A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the targ | Aug 25, 2022 | 7.5 | 19 | NO | NO |
CVE-2014-8583MEDIUM mod_wsgi before 4.2.4 for Apache, when creating a daemon process group, does not properly handle when group privileges cannot be dropped, which might allow attackers to gain privil | Dec 16, 2014 | 6.9 | 18 | NO | NO |
CVE-2014-0240MEDIUM The mod_wsgi module before 3.5 for Apache, when daemon mode is enabled, does not properly handle error codes returned by setuid when run on certain Linux kernels, which allows loca | May 27, 2014 | 6.2 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Modwsgi.
Media articles that mention a CVE ID that affects a product developed by Modwsgi — matched by CVE ID, not by vendor name.