CVE-2024-43799: Send Project Send

Medium severity, CVSS 4.7. EPSS: 0.5% chance of exploitation in the next 30 days.

Send is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendStream.redirect() which executes untrusted code. This issue is patched in send 0.19.0.

Affected products

Published 2024-09-10. Last modified 2026-06-17.