Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Pylons — Vulnerabilities & Security Advisories 14

Browse all 14 CVE security advisories affecting Pylons. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Pylons is a Python web framework used for building web applications and APIs. Historically, it has been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from improper input validation and insecure default configurations. While no major public security incidents have been widely documented, the 12 recorded CVEs highlight consistent security concerns, particularly in versions prior to 1.0. Developers should implement strict input sanitization, update regularly, and follow secure coding practices to mitigate risks associated with this framework.

CVE ID Title CVSS Severity Published
CVE-2026-54770 WebOb: Open redirect in Location header normalization via leading C0 control / space characters — webob CWE-601 6.1 Medium 2026-08-20
CVE-2026-44889 WebOb: Location header normalization during redirect leads to open redirect — webob CWE-601 6.1 Medium 2026-06-22
CVE-2024-49768 Waitress has request processing race condition in HTTP pipelining with invalid first request — waitress CWE-367 9.1 Critical 2024-10-29
CVE-2024-49769 Waitress has a denial of service leading to high CPU usage/resource exhaustion — waitress CWE-772 7.5 High 2024-10-29
CVE-2024-42353 WebOb's location header normalization during redirect leads to open redirect — webob CWE-601 6.1 Medium 2024-08-14
CVE-2023-40587 Pyramid static view path traversal up one directory — pyramid CWE-22 4.3 Medium 2023-08-25
CVE-2014-125056 Pylons horus services.py timing discrepancy — horus CWE-208 2.6 Low 2023-01-07
CVE-2022-31015 Uncaught Exception (due to a data race) leads to process termination in Waitress — waitress CWE-248 6.5 Medium 2022-05-31
CVE-2022-24761 HTTP Request Smuggling in waitress — waitress CWE-444 7.5 High 2022-03-17
CVE-2020-5236 Catastrophic backtracking in regex allows Denial of Service in Waitress — Waitress CWE-400 5.7 Medium 2020-02-04
CVE-2019-16792 HTTP Request Smuggling: Content-Length Sent Twice in Waitress — Waitress CWE-444 7.1 High 2020-01-22
CVE-2019-16789 HTTP Request Smuggling in Waitress: Invalid whitespace characters in headers — Waitress CWE-444 7.1 High 2019-12-26
CVE-2019-16785 HTTP Request Smuggling: LF vs CRLF handling in Waitress — Waitress CWE-444 7.1 High 2019-12-20
CVE-2019-16786 HTTP Request Smuggling: Invalid Transfer-Encoding in Waitress — Waitress CWE-444 7.1 High 2019-12-20

This page lists every published CVE security advisory associated with Pylons. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.