 waitress Documentation v1.4.0https://blog.zeddyu.info/2019/12/08/HTTP-Smuggling-en/ Waitress used to treat LF the same as CRLF in Transfer-Encoding: chunked requests, while the maintainer doesn't believe this could lead to a security issue validated to be properly framed with CRLF as required by RFC7230. Waitress now validates that the Transfer-Encoding header contains only transfer codes that it is able to decode. At the moment that includes the the only valid header value being chunked. That means that if the following header is sent: Transfer-Encoding: gzip, chunked Waitress will send back a 501 Not Implemented with an error message stating0 码力 | 48 页 | 54.34 KB | 1 年前3 waitress Documentation v1.4.0https://blog.zeddyu.info/2019/12/08/HTTP-Smuggling-en/ Waitress used to treat LF the same as CRLF in Transfer-Encoding: chunked requests, while the maintainer doesn't believe this could lead to a security issue validated to be properly framed with CRLF as required by RFC7230. Waitress now validates that the Transfer-Encoding header contains only transfer codes that it is able to decode. At the moment that includes the the only valid header value being chunked. That means that if the following header is sent: Transfer-Encoding: gzip, chunked Waitress will send back a 501 Not Implemented with an error message stating0 码力 | 48 页 | 54.34 KB | 1 年前3
 waitress Documentation v2.1.1GHSA-pg36-wpm5-g57p CVE-ID: CVE-2019-16785 Waitress used to treat LF the same as CRLF in Transfer-Encoding: chunked requests, while the maintainer doesn't believe this could lead to a security issue validated to be properly framed with CRLF as required by RFC7230. Waitress now validates that the Transfer-Encoding header contains only transfer codes that it is able to decode. At the moment that includes the the only valid header value being chunked. That means that if the following header is sent: Transfer-Encoding: gzip, chunked Waitress will send back a 501 Not Implemented with an error message stating0 码力 | 53 页 | 58.27 KB | 1 年前3 waitress Documentation v2.1.1GHSA-pg36-wpm5-g57p CVE-ID: CVE-2019-16785 Waitress used to treat LF the same as CRLF in Transfer-Encoding: chunked requests, while the maintainer doesn't believe this could lead to a security issue validated to be properly framed with CRLF as required by RFC7230. Waitress now validates that the Transfer-Encoding header contains only transfer codes that it is able to decode. At the moment that includes the the only valid header value being chunked. That means that if the following header is sent: Transfer-Encoding: gzip, chunked Waitress will send back a 501 Not Implemented with an error message stating0 码力 | 53 页 | 58.27 KB | 1 年前3
 waitress Documentation v2.1.0GHSA-pg36-wpm5-g57p CVE-ID: CVE-2019-16785 Waitress used to treat LF the same as CRLF in Transfer-Encoding: chunked requests, while the maintainer doesn't believe this could lead to a security issue validated to be properly framed with CRLF as required by RFC7230. Waitress now validates that the Transfer-Encoding header contains only transfer codes that it is able to decode. At the moment that includes the the only valid header value being chunked. That means that if the following header is sent: Transfer-Encoding: gzip, chunked Waitress will send back a 501 Not Implemented with an error message stating0 码力 | 52 页 | 57.95 KB | 1 年前3 waitress Documentation v2.1.0GHSA-pg36-wpm5-g57p CVE-ID: CVE-2019-16785 Waitress used to treat LF the same as CRLF in Transfer-Encoding: chunked requests, while the maintainer doesn't believe this could lead to a security issue validated to be properly framed with CRLF as required by RFC7230. Waitress now validates that the Transfer-Encoding header contains only transfer codes that it is able to decode. At the moment that includes the the only valid header value being chunked. That means that if the following header is sent: Transfer-Encoding: gzip, chunked Waitress will send back a 501 Not Implemented with an error message stating0 码力 | 52 页 | 57.95 KB | 1 年前3
 waitress Documentation v3.0.1
GHSA-pg36-wpm5-g57p CVE-ID: CVE-2019-16785 Waitress used to treat LF the same as CRLF in Transfer-Encoding: chunked requests, while the maintainer doesn't believe this could lead to a security issue validated to be properly framed with CRLF as required by RFC7230. Waitress now validates that the Transfer-Encoding header contains only transfer codes that it is able to decode. At the moment that includes the the only valid header value being chunked. That means that if the following header is sent: Transfer-Encoding: gzip, chunked Waitress will send back a 501 Not Implemented with an error message stating0 码力 | 55 页 | 56.36 KB | 1 年前3 waitress Documentation v3.0.1
GHSA-pg36-wpm5-g57p CVE-ID: CVE-2019-16785 Waitress used to treat LF the same as CRLF in Transfer-Encoding: chunked requests, while the maintainer doesn't believe this could lead to a security issue validated to be properly framed with CRLF as required by RFC7230. Waitress now validates that the Transfer-Encoding header contains only transfer codes that it is able to decode. At the moment that includes the the only valid header value being chunked. That means that if the following header is sent: Transfer-Encoding: gzip, chunked Waitress will send back a 501 Not Implemented with an error message stating0 码力 | 55 页 | 56.36 KB | 1 年前3
 waitress Documentation v1.1.0name as per RFC 2616. See https://github.com/Pylons/waitress/pull/44 When waitress receives a Transfer-Encoding: chunked request, we no longer send the TRANSFER_ENCODING nor the HTTP_TRANSFER_ENCODING value request is a non-chunked request with an accurate content-length. Cope with the fact that the Transfer-Encoding value is case-insensitive. When the --unix-socket-perms option was used as an argument to waitress- to console by default). Disallow WSGI applications to set “hop-by-hop” headers (Connection, Transfer-Encoding, etc). Don’t treat 304 status responses specially in HTTP/1.1 mode. Remove out of date interfaces0 码力 | 36 页 | 41.63 KB | 1 年前3 waitress Documentation v1.1.0name as per RFC 2616. See https://github.com/Pylons/waitress/pull/44 When waitress receives a Transfer-Encoding: chunked request, we no longer send the TRANSFER_ENCODING nor the HTTP_TRANSFER_ENCODING value request is a non-chunked request with an accurate content-length. Cope with the fact that the Transfer-Encoding value is case-insensitive. When the --unix-socket-perms option was used as an argument to waitress- to console by default). Disallow WSGI applications to set “hop-by-hop” headers (Connection, Transfer-Encoding, etc). Don’t treat 304 status responses specially in HTTP/1.1 mode. Remove out of date interfaces0 码力 | 36 页 | 41.63 KB | 1 年前3
 Tornado 6.0 Documentation
now responds with a 400 error instead of simply closing the connection. Content-Length and Transfer-Encoding headers are no longer sent with 1xx or 204 responses (this was already true of 304 responses) curl_httpclient Improved debug logging on Python 3. tornado.httpserver Content-Length and Transfer-Encoding headers are no longer sent with 1xx or 204 responses (this was already true of 304 responses) is_coroutine_function identifies functions wrapped by coroutine or engine. tornado.http1connection The Transfer-Encoding header is now parsed case-insensitively. tornado.httpclient SimpleAsyncHTTPClient now follows0 码力 | 869 页 | 692.83 KB | 1 年前3 Tornado 6.0 Documentation
now responds with a 400 error instead of simply closing the connection. Content-Length and Transfer-Encoding headers are no longer sent with 1xx or 204 responses (this was already true of 304 responses) curl_httpclient Improved debug logging on Python 3. tornado.httpserver Content-Length and Transfer-Encoding headers are no longer sent with 1xx or 204 responses (this was already true of 304 responses) is_coroutine_function identifies functions wrapped by coroutine or engine. tornado.http1connection The Transfer-Encoding header is now parsed case-insensitively. tornado.httpclient SimpleAsyncHTTPClient now follows0 码力 | 869 页 | 692.83 KB | 1 年前3
 Tornado 6.1 Documentation
now responds with a 400 error instead of simply closing the connection. Content-Length and Transfer-Encoding headers are no longer sent with 1xx or 204 responses (this was already true of 304 responses) curl_httpclient Improved debug logging on Python 3. tornado.httpserver Content-Length and Transfer-Encoding headers are no longer sent with 1xx or 204 responses (this was already true of 304 responses) is_coroutine_function identifies functions wrapped by coroutine or engine. tornado.http1connection The Transfer-Encoding header is now parsed case-insensitively. tornado.httpclient SimpleAsyncHTTPClient now follows0 码力 | 931 页 | 708.03 KB | 1 年前3 Tornado 6.1 Documentation
now responds with a 400 error instead of simply closing the connection. Content-Length and Transfer-Encoding headers are no longer sent with 1xx or 204 responses (this was already true of 304 responses) curl_httpclient Improved debug logging on Python 3. tornado.httpserver Content-Length and Transfer-Encoding headers are no longer sent with 1xx or 204 responses (this was already true of 304 responses) is_coroutine_function identifies functions wrapped by coroutine or engine. tornado.http1connection The Transfer-Encoding header is now parsed case-insensitively. tornado.httpclient SimpleAsyncHTTPClient now follows0 码力 | 931 页 | 708.03 KB | 1 年前3
 Tornado 6.5 Documentation[https://docs.python.org/3/library/functions.html#bool] Returns true if the headers specify Transfer-Encoding: chunked. Raise httputil.HTTPInputError if any other transfer encoding is used.Asynchronous CVE-2024-7592.What’s new in Tornado 6.4.1 Jun 6, 2024 Security Improvements Parsing of the Transfer-Encoding header is now stricter. Unexpected transfer- encoding values were previously ignored and treated in Tornado 6.3.3 Aug 11, 2023 Security improvements The Content-Length header and chunked Transfer-Encoding sizes are now parsed more strictly (according to the relevant RFCs) to avoid potential request-0 码力 | 437 页 | 405.14 KB | 3 月前3 Tornado 6.5 Documentation[https://docs.python.org/3/library/functions.html#bool] Returns true if the headers specify Transfer-Encoding: chunked. Raise httputil.HTTPInputError if any other transfer encoding is used.Asynchronous CVE-2024-7592.What’s new in Tornado 6.4.1 Jun 6, 2024 Security Improvements Parsing of the Transfer-Encoding header is now stricter. Unexpected transfer- encoding values were previously ignored and treated in Tornado 6.3.3 Aug 11, 2023 Security improvements The Content-Length header and chunked Transfer-Encoding sizes are now parsed more strictly (according to the relevant RFCs) to avoid potential request-0 码力 | 437 页 | 405.14 KB | 3 月前3
 Tornado 5.1 Documentation
now responds with a 400 error instead of simply closing the connection. Content-Length and Transfer-Encoding headers are no longer sent with 1xx or 204 responses (this was already true of 304 responses) curl_httpclient Improved debug logging on Python 3. tornado.httpserver Content-Length and Transfer-Encoding headers are no longer sent with 1xx or 204 responses (this was already true of 304 responses) is_coroutine_function identifies functions wrapped by coroutine or engine. tornado.http1connection The Transfer-Encoding header is now parsed case-insensitively. tornado.httpclient SimpleAsyncHTTPClient now follows0 码力 | 359 页 | 347.32 KB | 1 年前3 Tornado 5.1 Documentation
now responds with a 400 error instead of simply closing the connection. Content-Length and Transfer-Encoding headers are no longer sent with 1xx or 204 responses (this was already true of 304 responses) curl_httpclient Improved debug logging on Python 3. tornado.httpserver Content-Length and Transfer-Encoding headers are no longer sent with 1xx or 204 responses (this was already true of 304 responses) is_coroutine_function identifies functions wrapped by coroutine or engine. tornado.http1connection The Transfer-Encoding header is now parsed case-insensitively. tornado.httpclient SimpleAsyncHTTPClient now follows0 码力 | 359 页 | 347.32 KB | 1 年前3
 Tornado 6.4 Documentation
in Tornado 6.3.3 Aug 11, 2023 Security improvements The Content-Length header and chunked Transfer-Encoding sizes are now parsed more strictly (according to the relevant RFCs) to avoid potential request- now responds with a 400 error instead of simply closing the connection. Content-Length and Transfer-Encoding headers are no longer sent with 1xx or 204 responses (this was already true of 304 responses) curl_httpclient Improved debug logging on Python 3. tornado.httpserver Content-Length and Transfer-Encoding headers are no longer sent with 1xx or 204 responses (this was already true of 304 responses)0 码力 | 432 页 | 402.58 KB | 1 年前3 Tornado 6.4 Documentation
in Tornado 6.3.3 Aug 11, 2023 Security improvements The Content-Length header and chunked Transfer-Encoding sizes are now parsed more strictly (according to the relevant RFCs) to avoid potential request- now responds with a 400 error instead of simply closing the connection. Content-Length and Transfer-Encoding headers are no longer sent with 1xx or 204 responses (this was already true of 304 responses) curl_httpclient Improved debug logging on Python 3. tornado.httpserver Content-Length and Transfer-Encoding headers are no longer sent with 1xx or 204 responses (this was already true of 304 responses)0 码力 | 432 页 | 402.58 KB | 1 年前3
共 70 条
- 1
- 2
- 3
- 4
- 5
- 6
- 7














