An issue was discovered in webargs before 5.1.3, as used with marshmallow and other products. JSON parsing uses a short-lived cache to store the parsed JSON body. This cache is not thread-safe, meaning that incorrect JSON payloads could have been parsed for concurrent requests.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-03-12T02:00:00

Updated: 2024-08-04T22:01:53.274Z

Reserved: 2019-03-11T00:00:00

Link: CVE-2019-9710

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-03-12T02:29:00.273

Modified: 2019-03-12T13:09:58.037

Link: CVE-2019-9710

cve-icon Redhat

No data.