CVE-2024-1135
HighAdvisory
Published 16 Apr 2024In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.2
- base score, highest
- EPSS
- 0.030
- 87th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 126
- of 17,781 indexed, latest versions
- Container images
- 137
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Request smuggling leading to endpoint restriction bypass in Gunicorn
Carried by container images the latest versions of 126 of 17,781 indexed charts deploy, on 137 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| gunicornpypi | 19.6.0, 19.7.1, 19.8.0, 19.8.1+5 more | 22.0.0 | 137 |
- OSV records
- GHSA-w3h3-4rj7-4ph4
- Also known as
- PYSEC-2026-1434
Charts affected
126 by stars
Container images carrying it
137 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| cloudve/ | 4a3d7fae90bb | gunicorn | 22.0.0 | 3 |
| dpage/ | 781369df9994 | gunicorn | 22.0.0 | 3 |
| amancevice/ | 12a0a9e66550 | gunicorn | 22.0.0 | 2 |
| datawire/ | 8588eafe6862 | gunicorn | 22.0.0 | 2 |
| kodekloud/ | 3a856afb02a3 | gunicorn | 22.0.0 | 2 |
| larribas/ | 05ccb0b46bfb | gunicorn | 22.0.0 | 2 |
| lncm/ | 36eaa06f99f4 | gunicorn | 22.0.0 | 2 |
| ngoduykhanh/ | ba36ab196d3d | gunicorn | 22.0.0 | 2 |
| taigaio/ | fd4568a97a59 | gunicorn | 22.0.0 | 2 |
| allegroai/ | fca885e8cfc6 | gunicorn | 22.0.0 | 1 |
| amancevice/ | c8c04bfe3d66 | gunicorn | 22.0.0 | 1 |
| amundsendev/ | 69e7915e61c1 | gunicorn | 22.0.0 | 1 |
| amundsendev/ | 4d98eb21f5f9 | gunicorn | 22.0.0 | 1 |
| amundsendev/ | 99dda9502c3e | gunicorn | 22.0.0 | 1 |
| apache/ | 64e58748b6b9 | gunicorn | 22.0.0 | 1 |
| apache/ | e5560ad0b86e | gunicorn | 22.0.0 | 1 |
| apache/ | 975ab033580d | gunicorn | 22.0.0 | 1 |
| apache/ | ab9467fd712c | gunicorn | 22.0.0 | 1 |
| asdkant/ | a23d8bf7c885 | gunicorn | 22.0.0 | 1 |
| assistiot/ | 30812ba93555 | gunicorn | 22.0.0 | 1 |
| assistiot/ | 44a37b00d4f8 | gunicorn | 22.0.0 | 1 |
| assistiot/ | a942dc14030a | gunicorn | 22.0.0 | 1 |
| assistiot/ | e32b87786142 | gunicorn | 22.0.0 | 1 |
| bootc/ | f1383295e7be | gunicorn | 22.0.0 | 1 |
| buntha/ | 154542cc3083 | gunicorn | 22.0.0 | 1 |
| citizenstig/ | b81c818ccb86 | gunicorn | 22.0.0 | 1 |
| cleveritcz/ | c75c1636e0b7 | gunicorn | 22.0.0 | 1 |
| codecov/ | 0475cb1c3136 | gunicorn | 22.0.0 | 1 |
| datamate/ | 2dd66b722464 | gunicorn | 22.0.0 | 1 |
| datawire/ | 07f8fe4f4f8e | gunicorn | 22.0.0 | 1 |
| datawire/ | 2beb65062c8b | gunicorn | 22.0.0 | 1 |
| datawire/ | 9716efbdd24b | gunicorn | 22.0.0 | 1 |
| ddosify/ | a43c5155fa1c | gunicorn | 22.0.0 | 1 |
| ddosify/ | 3c11e3182652 | gunicorn | 22.0.0 | 1 |
| ddosify/ | ac323d52bfb4 | gunicorn | 22.0.0 | 1 |
| ddosify/ | 71b8768f49bc | gunicorn | 22.0.0 | 1 |
| ddosify/ | b796b8c73011 | gunicorn | 22.0.0 | 1 |
| douz/ | 4384103d0219 | gunicorn | 22.0.0 | 1 |
| dpage/ | 18cd5711fc9a | gunicorn | 22.0.0 | 1 |
| dpage/ | 37946e4f3e7b | gunicorn | 22.0.0 | 1 |
| dpage/ | a5a656e1d5fd | gunicorn | 22.0.0 | 1 |
| dpage/ | b1f00b8163cf | gunicorn | 22.0.0 | 1 |
| elastichq/ | bb3bd22c2b87 | gunicorn | 22.0.0 | 1 |
| evk02/ | ef6ff257ef35 | gunicorn | 22.0.0 | 1 |
| factly/ | ca5bc71d1d5c | gunicorn | 22.0.0 | 1 |
| fiware/ | 3e3ec88d59ed | gunicorn | 22.0.0 | 1 |
| fiware/ | 29456835bb2c | gunicorn | 22.0.0 | 1 |
| fiware/ | c3c1c8ccfb45 | gunicorn | 22.0.0 | 1 |
| flagsmith/ | fd58556339a4 | gunicorn | 22.0.0 | 1 |
| galaxy/ | e5c265fe9fcd | gunicorn | 22.0.0 | 1 |