Skip to content

Commit de3324d

Browse files
Add documentation for security issue
1 parent 3bcd690 commit de3324d

File tree

1 file changed

+14
-0
lines changed

1 file changed

+14
-0
lines changed

CHANGES.txt

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,17 @@
1+
1.4.1 (2019-12-??)
2+
------------------
3+
4+
Security Fixes
5+
~~~~~~~~~~~~~~
6+
7+
- Waitress did not properly validate that the HTTP headers it received were
8+
properly formed, thereby potentially allowing a front-end server to treat a
9+
request different from Waitress. This could lead to HTTP request
10+
smuggling/splitting.
11+
12+
Please see the security advisory for more information:
13+
https://github.com/Pylons/waitress/security/advisories/GHSA-m5ff-3wj3-8ph4
14+
115
1.4.0 (2019-12-20)
216
------------------
317

0 commit comments

Comments
 (0)