© 2025-2026 PySpect
First version without a known vulnerability: 3.0.1
Waitress has request processing race condition in HTTP pipelining with invalid first request
Fixed in: 3.0.1, e4359018537af376cf24bd13616d861e2fb76f65
Waitress vulnerable to DoS leading to high CPU usage/resource exhaustion
Fixed in: 3.0.1, 1ae4e894c9f76543bee06584001583fc6fa8c95c
Uncaught Exception (due to a data race) leads to process termination in Waitress
Fixed in: 2.1.2, 4f6789b035610e0552738cdc4b35ca809a592d48
HTTP Request Smuggling in waitress
Fixed in: 2.1.1, 9e0b8c801e4d505c2ffc91b891af4ba48af715e0
Catastrophic backtracking in regex allows Denial of Service in Waitress
Fixed in: 1.4.3, 6e46f9e3f014d64dd7d1e258eaf626e39870ee1f
HTTP Request Smuggling in Waitress: Invalid whitespace characters in headers (Follow-up)
Fixed in: 1.4.2, 11d9e138125ad46e951027184b13242a3c1de017, 1.4.1
HTTP Request Smuggling: Invalid whitespace characters in headers in Waitress
Fixed in: 1.4.1
HTTP Request Smuggling: Content-Length Sent Twice in Waitress
Fixed in: 1.4.0, 575994cd42e83fd772a5f7ec98b2c56751bd3f65
HTTP Request Smuggling: Invalid Transfer-Encoding in Waitress
Fixed in: 1.4.0, f11093a6b3240fc26830b6111e826128af7771c3, 1.3.1
HTTP Request Smuggling: LF vs CRLF handling in Waitress
Fixed in: 1.4.0, 8eba394ad75deaf9e5cd15b78a3d16b12e6b0eba