cbcvebase.
CVE-2020-26116
published 2020-09-27

CVE-2020-26116: http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the…

PriorityP347high7.2CVSS 3.1
AVNACLPRNUINSCCLILAN
EPSS
6.42%
92.9th percentile
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianpypy3< pypy3 7.3.3+dfsg-1 (bookworm)pypy3 7.3.3+dfsg-1 (bookworm)
debianpython-urllib3< python-urllib3 1.25.9-1 (bookworm)python-urllib3 1.25.9-1 (bookworm)
debianpython2.7< pypy3 7.3.3+dfsg-1 (bookworm)pypy3 7.3.3+dfsg-1 (bookworm)
debianpython3.9< pypy3 7.3.3+dfsg-1 (bookworm)pypy3 7.3.3+dfsg-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
msrccbl2_python-virtualenv_20.26.6-1_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_python-urllib3_1.25.9-2_on_cbl_mariner_1.0
msrccm1_python3_3.7.10-3_on_cbl_mariner_1.0
opensuseleap
oraclecommunications_cloud_native_core_network_function_cloud_native_environment
oraclezfs_storage_appliance_kit
pythonpython>= 3.0.0 < 3.5.103.5.10
pythonpython>= 3.6.0 < 3.6.123.6.12
pythonpython>= 3.7.0 < 3.7.93.7.9
pythonpython>= 3.8.0 < 3.8.53.8.5

CVSS provenance

nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
ghsa7.2HIGH
osv7.6HIGH
vendor_ubuntu7.6HIGH
vendor_debian7.2HIGH
vendor_msrc7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.