pypi package report

Is quart safe?

2 known vulnerabilities, worst severity HIGH.

// reach

10 direct dependencies

4 carry known advisories, worst HIGH

12 packages depend on it

an advisory here reaches each of them

Create a free accountfor every dependency path, dependent and what to upgrade
// ai model usage

No published models are known to use this package.


cvss
0.0
high

severity band, no base score published

epss
not scored

chance of exploitation in 30 days

xyz score
not scored

CyberXYZ composite out of 10

fig. 01 — GHSA-v853-p72q-4cfw, the advisory selected below

// 2 advisories

GHSA-v853-p72q-4cfw

HIGH
// summary

Quart 0.23.0 contains a stray debug statement (print(data)) inside Body.await in quart/wrappers/request.py. Any request whose body is awaited — await request.form, await request.getdata(), WTForms validateonsubmit(), etc. — has its raw, unparsed body printed to stdout, including plaintext form fields such as passwords and CSRF tokens. Confirmed present in 0.23.0, confirmed absent in 0.22.0.

// details

In src/quart/wrappers/request.py, Body.await accumulates the request body into a bytearray:

​python data = bytearray() while not self.queue.empty(): data.extend(self.queue.getnowait()) print(data) # self.maxcontentlength ): raise RequestEntityTooLarge() ​

This fires for every request that awaits its body — the overwhelming majority of POST/PUT routes in a typical Quart app (form submissions, JSON APIs via request.getjson(), file uploads, etc.).

// poc
  • pip install quart==0.23.0 (requires Python 3.13+)
  • Minimal route:

​python @app.route("/login", methods=["POST"]) async def login(): formdata = await request.form ... ​

  • Submit a POST with form data, e.g. a login form with staffid/password fields.
  • Observe stdout: the full raw body is printed as bytearray(b'csrftoken=...&staffid=...&password=...').

Confirmed via source diff against 0.22.0's request.py, where this line does not exist.

// impact

Any app that captures stdout in logs (terminal redirect, systemd/journald, Docker logs, cloud log aggregation, etc.) will have every submitted form body — including login credentials — written to logs in plaintext. This affects any Quart 0.23.0 app handling authentication or any sensitive form data, and is trivially triggerable by any user simply submitting a form (no attacker action required beyond normal use).


Checked 2026-10-06 at 02:00 UTC. The most recent advisory here was published 2026-10-05. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.