← Back

CVE-2020-26116

nvd nist
Published: Sep 27, 2020Modified: Jun 17, 2026

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Exploitability: 3.9 / Impact: 2.7
Source: NVD

Description

http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.

Affected (16)

Products: Python: Python · Fedoraproject: Fedora · Canonical: Ubuntu Linux · +4 more
Show all products
1 product
Python
1 product
Fedora
1 product
Ubuntu Linux
2 products
Hci Storage Node
Solidfire
1 product
Debian Linux
1 product
Zfs Storage Appliance Kit
1 product
Leap
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Python
From 3.0.0 to 3.5.10
From 3.6.0 to 3.6.12
From 3.7.0 to 3.7.9
From 3.8.0 to 3.8.5
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 31
Version 32
Version 33
Configuration C
4 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 12.04
Version 14.04
Version 16.04
Version 18.04
Configuration D
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
All versions
Running on/withPlatform Versions
Netapp
Hci Compute Node
All versions
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.8
Configuration G
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 15.1

References (28)

Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
ExploitIssue TrackingPatchVendor Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.