VYPR
High severity7.5NVD Advisory· Published Feb 26, 2018· Updated Jun 17, 2026

CVE-2018-7490

CVE-2018-7490

Description

uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
uWSGIPyPI
< 2.0.172.0.17

Affected products

4
  • ghsa-coords
    Range: < 2.0.17
  • cpe:2.3:a:unbit:uwsgi:*:*:*:*:*:*:*:*
    Range: <2.0.17
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.