cbcvebase.
CVE-2024-49769
published 2024-10-29

CVE-2024-49769: Waitress is a Web Server Gateway Interface server for Python 2 and 3. When a remote client closes the connection before waitress has had the opportunity to…

PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.39%
69.2th percentile
Waitress is a Web Server Gateway Interface server for Python 2 and 3. When a remote client closes the connection before waitress has had the opportunity to call getpeername() waitress won't correctly clean up the connection leading to the main thread attempting to write to a socket that no longer exists, but not removing it from the list of sockets to attempt to process. This leads to a busy-loop calling the write function. A remote attacker could run waitress out of available sockets with very little resources required. Waitress 3.0.1 contains fixes that remove the race condition.

Affected

12 ranges
VendorProductVersion rangeFixed in
agendalesswaitress< 3.0.13.0.1
debianwaitress< waitress 2.1.2-2+deb12u1 (bookworm)waitress 2.1.2-2+deb12u1 (bookworm)
msrcazl3_python-waitress_3.0.1-1_on_azure_linux_3.0
pylonswaitress< 3.0.13.0.1
pylonswaitress>= 0 < 1.4.4-1.1+deb11u21.4.4-1.1+deb11u2
pylonswaitress>= 0 < 2.1.2-2+deb12u12.1.2-2+deb12u1
pylonswaitress>= 0 < 3.0.1-13.0.1-1
pylonswaitress>= 0 < 3.0.1-13.0.1-1
pylonswaitress>= 0 < 3.0.13.0.1
pylonswaitress>= 0 < 1.4.1-1ubuntu0.21.4.1-1ubuntu0.2
pylonswaitress>= 0 < 1.4.4-1.1ubuntu1.11.4.4-1.1ubuntu1.1
pylonswaitress>= 0 < 2.1.2-2ubuntu0.1~esm12.1.2-2ubuntu0.1~esm1

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu9.1CRITICAL
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.