GHSA-v853-p72q-4cfwHigh· 7.5▾ TwilightQuart leaks raw request body (incl. plaintext passwords) to stdout via stray debug print in Body.__await__
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Quart 0.23.0 contains a stray debug statement (print(data)) inside Body.__await__ in quart/wrappers/request.py. Any request whose body is awaited — await request.form, await request.get_data(), WTForms validate_on_submit(), etc. — has its raw, unparsed body printed to stdout, including plaintext form fields such as passwords and CSRF tokens. Confirmed present in 0.23.0, confirmed absent in 0.22.0.
In src/quart/wrappers/request.py, Body.__await__ accumulates the request body into a bytearray:
python data = bytearray() while not self._queue.empty(): data.extend(self._queue.get_nowait()) print(data) # <-- not present in 0.22.0 if ( self._max_content_length is not None and len(data) > self._max_content_length ): raise RequestEntityTooLarge()
This fires for every request that awaits its body — the overwhelming majority of POST/PUT routes in a typical Quart app (form submissions, JSON APIs via request.get_json(), file uploads, etc.).
pip install quart==0.23.0 (requires Python 3.13+)python @app.route("/login", methods=["POST"]) async def login(): form_data = await request.form ... staff_id/password fields.bytearray(b'csrf_token=...&staff_id=...&password=...').Confirmed via source diff against 0.22.0's request.py, where this line does not exist.
Any app that captures stdout in logs (terminal redirect, systemd/journald, Docker logs, cloud log aggregation, etc.) will have every submitted form body — including login credentials — written to logs in plaintext. This affects any Quart 0.23.0 app handling authentication or any sensitive form data, and is trivially triggerable by any user simply submitting a form (no attacker action required beyond normal use).
quart = 0.23.0Upgrade to a patched release:
quart 0.23.1Connected by shared product, vendor, weakness, or advisory.
CVE-2019-1953Medium· 6.5A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to view a password in clear text
CVE-2024-23686Medium· 5.3DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an attacker to recover the NVD API Key from a log file.
CVE-2023-43261High· 7.5An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.
CVE-2026-86049High· 7.1Jupyter Server is the backend for Jupyter web applications
CVE-2026-74870Low· 3.3openssl_encrypt before 1.4.8 Hardware Pepper Information Disclosure
CVE-2025-66236High· 7.5Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to security details and security model of Airflow