uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal.
"https://github.com/pypa/advisory-database/blob/main/vulns/uwsgi/PYSEC-2018-78.yaml"