CVE-2014-0242: Modwsgi Mod Wsgi

High severity, CVSS 7.5. EPSS: 8.5% chance of exploitation in the next 30 days.

mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from memory that may have been freed and then overwritten by a separate thread.

Affected products

  • Modwsgi Mod Wsgi: before 3.4 (fixed in 3.4)

Published 2019-12-09. Last modified 2026-06-17.