GHSA-v853-p72q-4cfw
### Summary Quart 0.23.0 contains a stray debug statement (`print(data)`) inside `Body.__await__` in `quart/wrappers/request.py`. Any request whose body is awaited — `await request.form`, `await request.get_data()`, WTForms `validate_on_submit()`, etc. — has its raw, unparsed body printed to stdout, including plaintext form fields such as passwords and CSRF tokens. Confirmed present in 0.23.0, confirmed absent in 0.22.0. ### Details In `src/quart/wrappers/request.py`, `Body.__await__` accumulates the request body into a bytearray: ```python data = bytearray() while not self._queue.empty(): data.extend(self._queue.get_nowait()) print(data) # <-- not present in 0.22.0 if ( self._max_content_length is not None and len(data) > self._max_content_length ): raise RequestEntityTooLarge() ``` This fires for every request that awaits its body — the overwhelming majority of POST/PUT routes in a typical Quart app (form submissions, JSON APIs via `request.get_json()`, file uploads, etc.). ### PoC 1. `pip install quart==0.23.0` (requires Python 3.13+) 2. Minimal route: ```python @app.route("/login", methods=["POST"]) async def login(): form_data = await request.form ... ``` 3. Submit a POST with form data, e.g. a login form with `staff_id`/`password` fields. 4. Observe stdout: the full raw body is printed as `bytearray(b'csrf_token=...&staff_id=...&password=...')`. Confirmed via source diff against 0.22.0's `request.py`, where this line does not exist. ### Impact Any app that captures stdout in logs (terminal redirect, systemd/journald, Docker logs, cloud log aggregation, etc.) will have every submitted form body — including login credentials — written to logs in plaintext. This affects any Quart 0.23.0 app handling authentication or any sensitive form data, and is trivially triggerable by any user simply submitting a form (no attacker action required beyond normal use).
Properties
- summary
- Quart leaks raw request body (incl. plaintext passwords) to stdout via stray debug print in Body.__await__
- severity
- high
- cvss_score
- 7.5
- retrieved_at
- 2026-10-05T22:59:07+00:00
- ghsa_published
- 2026-10-05T22:49:44Z
- source_url
- https://github.com/advisories/GHSA-v853-p72q-4cfw
- ghsa_updated
- 2026-10-05T22:49:45Z
- ghsa_id
- GHSA-v853-p72q-4cfw
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-v853-p72q-4cfw
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- signal_observed_at
- 2026-10-05T22:59:07+00:00
- is_ghsa_only
- true
Related Entities (4)
HAS_WEAKNESS (1)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
Explore deeper with Ninja Signal's threat intelligence graph