Vulnerability record · CVE-2018-7490 · published 26 February 2018
CVE-2018-7490: uWSGI --php-docroot check bypass allows directory traversal
Unbit · Uwsgi
uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check when the --php-docroot option is used, permitting directory traversal. The flaw is a path traversal (CWE-22) that exposes files outside the intended PHP document root. It matters because the affected option is used to serve PHP content, and the record gives no indication that exploitation requires credentials.
Description
uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityHigh CVSS (7.5) with no authentication required, public exploit code, and very high EPSS, though not listed in KEV.
What it is
uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check when the --php-docroot option is used, permitting directory traversal. The flaw is a path traversal (CWE-22) that exposes files outside the intended PHP document root. It matters because the affected option is used to serve PHP content, and the record gives no indication that exploitation requires credentials.
Impact
An attacker can read files outside the configured PHP document root, gaining access to data the server intended to keep out of reach. The CVSS vector rates confidentiality impact as high with no integrity or availability impact.
Attack surface
Reachable over the network via HTTP requests to a uWSGI instance running with the --php-docroot option; the CVSS vector shows no privileges required and no user interaction. The description does not state whether the affected option is enabled by default, so exposure depends on that configuration.
Exploitation
CISA KEV does not list this CVE, but EPSS is high at roughly 0.69 (99th percentile), and a public Exploit-DB entry (44223) exists, indicating exploit code is available. The record does not confirm observed in-the-wild exploitation.
What to do
- Upgrade uWSGI to 2.0.17 or later, which the vendor changelog identifies as the fix.
- Apply the Debian security update DSA-4142 if running the distribution package.
- If upgrading is not immediately possible, disable or avoid the --php-docroot option and restrict filesystem permissions for the uWSGI process.
- Limit network access to uWSGI/PHP endpoints to trusted clients until patched.
Detection
- Inspect HTTP request logs for traversal sequences such as ../ or encoded variants targeting PHP-handled paths.
- Monitor for requests returning files outside the configured document root, especially configuration or credential files.
- Alert on uWSGI processes running with --php-docroot and correlate with unusual file-read patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://uwsgi-docs.readthedocs.io/en/latest/Changelog-2.0.17.html | Vendor Advisory |
| https://www.debian.org/security/2018/dsa-4142 | Third Party Advisory |
| https://www.exploit-db.com/exploits/44223/ | Third Party AdvisoryVDB Entry |
| https://uwsgi-docs.readthedocs.io/en/latest/Changelog-2.0.17.html | Vendor Advisory |
| https://www.debian.org/security/2018/dsa-4142 | Third Party Advisory |
| https://www.exploit-db.com/exploits/44223/ | Third Party AdvisoryVDB Entry |
Track CVE-2018-7490 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-7490), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.