{"api_version":"v1","generated_at":"2026-10-08T02:45:00+00:00","product":{"cve_count":5,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-pylons-waitress-af5ccaf8520b","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/waitress","name":"waitress","next_cursor":null,"observations":[{"affected":">= 2.0.0, < 3.0.1","affected_versions_present":true,"cve_id":"CVE-2024-49768","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-49768","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-10-29T14:56:02.111Z","patch_url":"https://github.com/Pylons/waitress/commit/e4359018537af376cf24bd13616d861e2fb76f65","primary_source":"","published":"2024-10-29T14:32:25.164Z"},{"affected":"< 3.0.1","affected_versions_present":true,"cve_id":"CVE-2024-49769","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-49769","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-11-17T00:11:26.954Z","patch_url":"https://github.com/Pylons/waitress/pull/435","primary_source":"","published":"2024-10-29T14:18:40.951Z"},{"affected":">= 2.1.0, < 2.1.2","affected_versions_present":true,"cve_id":"CVE-2022-31015","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-31015","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-22T17:55:26.641Z","patch_url":"https://github.com/Pylons/waitress/issues/374","primary_source":"","published":"2022-05-31T22:50:12.000Z"},{"affected":"< 2.1.1","affected_versions_present":true,"cve_id":"CVE-2022-24761","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-24761","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T18:46:46.567Z","patch_url":"https://github.com/Pylons/waitress/commit/9e0b8c801e4d505c2ffc91b891af4ba48af715e0","primary_source":"","published":"2022-03-17T12:40:10.000Z"},{"affected":"= 1.4.2","affected_versions_present":true,"cve_id":"CVE-2020-5236","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-5236","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T08:22:09.008Z","patch_url":"https://github.com/Pylons/waitress/commit/6e46f9e3f014d64dd7d1e258eaf626e39870ee1f","primary_source":"","published":"2020-02-04T03:05:14.000Z"},{"affected":"<= 1.3.1 \u2264 1.3.1","affected_versions_present":true,"cve_id":"CVE-2019-16792","cve_url":"https://cve.blacktree.nl/cve/CVE-2019-16792","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-05T01:24:48.422Z","patch_url":"https://www.oracle.com/security-alerts/cpuapr2022.html","primary_source":"","published":"2020-01-22T18:30:15.000Z"},{"affected":"< 1.4.1 < 1.4.1","affected_versions_present":true,"cve_id":"CVE-2019-16789","cve_url":"https://cve.blacktree.nl/cve/CVE-2019-16789","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-05T01:24:48.331Z","patch_url":"https://www.oracle.com/security-alerts/cpuapr2022.html","primary_source":"","published":"2019-12-26T16:40:12.000Z"},{"affected":"<= 1.3.1 \u2264 1.3.1","affected_versions_present":true,"cve_id":"CVE-2019-16785","cve_url":"https://cve.blacktree.nl/cve/CVE-2019-16785","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-05T01:24:47.876Z","patch_url":"https://www.oracle.com/security-alerts/cpuapr2022.html","primary_source":"","published":"2019-12-20T23:00:25.000Z"},{"affected":"<= 1.3.1 \u2264 1.3.1","affected_versions_present":true,"cve_id":"CVE-2019-16786","cve_url":"https://cve.blacktree.nl/cve/CVE-2019-16786","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-05T01:24:48.017Z","patch_url":"https://www.oracle.com/security-alerts/cpuapr2022.html","primary_source":"","published":"2019-12-20T23:00:20.000Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"Pylons"}}
