VYPR
High severity8.8NVD Advisory· Published Jan 29, 2020· Updated Jun 17, 2026

CVE-2020-7965

CVE-2020-7965

Description

flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receiving JSON input. If the request body is valid JSON, it will accept it even if the content type is application/x-www-form-urlencoded. This allows for JSON POST requests to be made across domains, leading to CSRF.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
webargsPyPI
>= 5.0.0, < 5.5.35.5.3
webargsPyPI
>= 6.0.0b1, < 6.0.0b46.0.0b4

Affected products

3

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.