[pkg-uWSGI-devel] Fwd: Possible uWSGI security vulnerability

Carlos Pastor carlos.pastor at outboxcoaching.com
Fri Sep 4 22:17:01 BST 2026


Dear package managers,

Let me forward you the email I have sent to info at unbit.it, in case
there is noone watching the inbox.

I am unsure how to handle it, as it is semi-public at this point? If
this is not the preferred reporting medium, please let me know.

Best regards,
Carlos Pastor

---------- Forwarded message ---------
From: Carlos Pastor <carlos.pastor at outboxcoaching.com>
Date: Fri, Sep 4, 2026 at 10:44 PM
Subject: Possible uWSGI security vulnerability
To: <info at unbit.it>


Hello, and sorry for reaching you over email.

core/utils.c function check_hex is clearly wrong, and allows non-hex
characters through.

It seems to be only called from core/progress.c function
uwsgi_upload_progress_create.

I don't have enough knowledge to research the security implications,
but it doesn't look good. It is also kind of public, as at least one
unrelated PR fixes it #2766 (might have been autofixed by some coding
tool?).

I know the project is heavily unmaintained, but I thought I would let you know.

Best regards,
Carlos Pastor



More information about the pkg-uWSGI-devel mailing list