CVE-2024-6827

CVSS 3.0 Score 7.5 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 444

Summary

CVE-2024-6827 is a newly disclosed vulnerability affecting Gunicorn version 21.2.0. The issue lies in the application's failure to adhere to RFC standards when validating the 'Transfer-Encoding' header. This oversight enables TE.CL request smuggling, which can result in various attack vectors such as cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Attackers can potentially inject malicious requests, causing unintended server behavior and potential data breaches. It is strongly recommended to update to a patched version of Gunicorn to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Gunicorn

Affected Vendors

  • Gunicorn Developer