uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal.
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2018-7490.json"