GHSA-v853-p72q-4cfw

Suggest an improvement
Source
https://github.com/advisories/GHSA-v853-p72q-4cfw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-v853-p72q-4cfw/GHSA-v853-p72q-4cfw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-v853-p72q-4cfw
Published
2026-10-05T22:49:44Z
Modified
2026-10-05T23:00:06Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Quart leaks raw request body (incl. plaintext passwords) to stdout via stray debug print in Body.__await__
Details

Summary

Quart 0.23.0 contains a stray debug statement (print(data)) inside Body.__await__ in quart/wrappers/request.py. Any request whose body is awaited — await request.form, await request.get_data(), WTForms validate_on_submit(), etc. — has its raw, unparsed body printed to stdout, including plaintext form fields such as passwords and CSRF tokens. Confirmed present in 0.23.0, confirmed absent in 0.22.0.

Details

In src/quart/wrappers/request.py, Body.__await__ accumulates the request body into a bytearray:

​python data = bytearray() while not self._queue.empty(): data.extend(self._queue.get_nowait()) print(data) # <-- not present in 0.22.0 if ( self._max_content_length is not None and len(data) > self._max_content_length ): raise RequestEntityTooLarge() ​

This fires for every request that awaits its body — the overwhelming majority of POST/PUT routes in a typical Quart app (form submissions, JSON APIs via request.get_json(), file uploads, etc.).

PoC

  1. pip install quart==0.23.0 (requires Python 3.13+)
  2. Minimal route: ​python @app.route("/login", methods=["POST"]) async def login(): form_data = await request.form ... ​
  3. Submit a POST with form data, e.g. a login form with staff_id/password fields.
  4. Observe stdout: the full raw body is printed as bytearray(b'csrf_token=...&staff_id=...&password=...').

Confirmed via source diff against 0.22.0's request.py, where this line does not exist.

Impact

Any app that captures stdout in logs (terminal redirect, systemd/journald, Docker logs, cloud log aggregation, etc.) will have every submitted form body — including login credentials — written to logs in plaintext. This affects any Quart 0.23.0 app handling authentication or any sensitive form data, and is trivially triggerable by any user simply submitting a form (no attacker action required beyond normal use).

Database specific
{
    "cwe_ids":  [
        "CWE-532"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-10-05T22:49:44Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

PyPI / quart

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.23.0
Fixed
0.23.1

Affected versions

0.*
0.23.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-v853-p72q-4cfw/GHSA-v853-p72q-4cfw.json"