uvicorn@0.12.0 vulnerabilities

The lightning-fast ASGI server.

Direct Vulnerabilities

Known vulnerabilities in the uvicorn package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Race Condition

uvicorn is a lightning-fast ASGI server.

Affected versions of this package are vulnerable to Race Condition in the uvicorn/protocols/http component that leads Quart to hang with uvicorn. This vulnerability may allow an attacker to disrupt the server's response handling process under certain conditions, leading to potential Denial of Service (DoS) or other adverse impacts.

How to fix Race Condition?

Upgrade uvicorn to version 0.12.3 or higher.

[,0.12.3)