ahmetoner / whisper-asr-webservice

OpenAI Whisper ASR Webservice API
https://ahmetoner.github.io/whisper-asr-webservice
MIT License
1.85k stars 331 forks source link

[Important] HTTP Request Smuggling #217

Open ostpachukAndrii opened 1 month ago

ostpachukAndrii commented 1 month ago

Dear Whisper-ASR-Webservice Team,

I hope this message finds you well.

I regret to inform you that a critical security vulnerability has been identified in one of service dependencies, specifically gunicorn version 21.2.0. It is imperative that we upgrade to version 22.0.0 immediately to address this issue.

The vulnerability in question pertains to HTTP Request Smuggling, resulting from improper validation of Transfer-Encoding headers within affected versions. This flaw could potentially enable attackers to circumvent security measures and gain unauthorized access to restricted endpoints by crafting requests with conflicting Transfer-Encoding headers.

Given the severity of this issue, I urge everyone to prioritize the update process without delay.

Thank you for your swift attent!