We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 3bcd690 commit de3324dCopy full SHA for de3324d
CHANGES.txt
@@ -1,3 +1,17 @@
1
+1.4.1 (2019-12-??)
2
+------------------
3
+
4
+Security Fixes
5
+~~~~~~~~~~~~~~
6
7
+- Waitress did not properly validate that the HTTP headers it received were
8
+ properly formed, thereby potentially allowing a front-end server to treat a
9
+ request different from Waitress. This could lead to HTTP request
10
+ smuggling/splitting.
11
12
+ Please see the security advisory for more information:
13
+ https://github.com/Pylons/waitress/security/advisories/GHSA-m5ff-3wj3-8ph4
14
15
1.4.0 (2019-12-20)
16
------------------
17
0 commit comments