[pkg-uWSGI-devel] Fwd: Possible uWSGI security vulnerability
Carlos Pastor
carlos.pastor at outboxcoaching.com
Fri Sep 4 22:17:01 BST 2026
Dear package managers,
Let me forward you the email I have sent to info at unbit.it, in case
there is noone watching the inbox.
I am unsure how to handle it, as it is semi-public at this point? If
this is not the preferred reporting medium, please let me know.
Best regards,
Carlos Pastor
---------- Forwarded message ---------
From: Carlos Pastor <carlos.pastor at outboxcoaching.com>
Date: Fri, Sep 4, 2026 at 10:44 PM
Subject: Possible uWSGI security vulnerability
To: <info at unbit.it>
Hello, and sorry for reaching you over email.
core/utils.c function check_hex is clearly wrong, and allows non-hex
characters through.
It seems to be only called from core/progress.c function
uwsgi_upload_progress_create.
I don't have enough knowledge to research the security implications,
but it doesn't look good. It is also kind of public, as at least one
unrelated PR fixes it #2766 (might have been autofixed by some coding
tool?).
I know the project is heavily unmaintained, but I thought I would let you know.
Best regards,
Carlos Pastor
More information about the pkg-uWSGI-devel
mailing list