Unbit maintains uWSGI, a widely deployed Python application server and gateway interface that bridges web applications to HTTP servers, exposing a parser and request-handling attack surface. The observed vulnerability pattern centers on input-validation and path-restriction weaknesses including path traversal, HTTP request smuggling, and out-of-bounds writes, reflecting the complexity of correctly parsing and constraining untrusted network requests in a translation-layer role.
The number and severity of CVEs published that impact products developed by Unbit over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-7490HIGH uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal. | Feb 26, 2018 | 7.5 | 79 | NO | YES |
CVE-2018-6758CRITICAL The uwsgi_expand_path function in core/utils.c in Unbit uWSGI through 2.0.15 has a stack-based buffer overflow via a large directory length. | Feb 6, 2018 | 9.8 | 30 | NO | NO |
CVE-2023-27522HIGH HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55.
Special characters in the origi | Mar 7, 2023 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unbit.
Media articles that mention a CVE ID that affects a product developed by Unbit — matched by CVE ID, not by vendor name.