CVE-2018-6758: Unbit Uwsgi

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

The uwsgi_expand_path function in core/utils.c in Unbit uWSGI through 2.0.15 has a stack-based buffer overflow via a large directory length.

Affected products

  • Unbit Uwsgi: up to and including 2.0.15

Published 2018-02-06. Last modified 2026-06-17.