CVE-2020-26116
published 2020-09-27CVE-2020-26116: http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the…
PriorityP347high7.2CVSS 3.1
AVNACLPRNUINSCCLILAN
EPSS
6.42%
92.9th percentile
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | pypy3 | < pypy3 7.3.3+dfsg-1 (bookworm) | pypy3 7.3.3+dfsg-1 (bookworm) |
| debian | python-urllib3 | < python-urllib3 1.25.9-1 (bookworm) | python-urllib3 1.25.9-1 (bookworm) |
| debian | python2.7 | < pypy3 7.3.3+dfsg-1 (bookworm) | pypy3 7.3.3+dfsg-1 (bookworm) |
| debian | python3.9 | < pypy3 7.3.3+dfsg-1 (bookworm) | pypy3 7.3.3+dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_python-virtualenv_20.26.6-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_python-urllib3_1.25.9-2_on_cbl_mariner_1.0 | — | — |
| msrc | cm1_python3_3.7.10-3_on_cbl_mariner_1.0 | — | — |
| opensuse | leap | — | — |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
| python | python | >= 3.0.0 < 3.5.10 | 3.5.10 |
| python | python | >= 3.6.0 < 3.6.12 | 3.6.12 |
| python | python | >= 3.7.0 < 3.7.9 | 3.7.9 |
| python | python | >= 3.8.0 < 3.8.5 | 3.8.5 |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
ghsa7.2HIGH
osv7.6HIGH
vendor_ubuntu7.6HIGH
vendor_debian7.2HIGH
vendor_msrc7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
osv·2024-07-11·CVSS 7.6
CVE-2015-20107 [HIGH] python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
It was discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.
(CVE-2015-20107)
It was discovered that Python incorrectly used regular expressions
vulnerable to catastrophic backtracking. A remote attacker could possibly
use this issue to cause a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2018-1060, CVE-2018-1061)
It was discovered that Python failed to initialize Expat’s hash salt. A
remote attacker could possibly use this issue to cause hash collisions,
leading to a denial of service. This issue only affected Ubuntu 14.04 L
GHSA
GHSA-w7gf-rpqw-gx4f: http
ghsa_unreviewed·2022-05-24
CVE-2020-26116 [HIGH] CWE-116 GHSA-w7gf-rpqw-gx4f: http
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
OSV
CRLF injection in urllib3
osv·2021-06-18·CVSS 7.2
CVE-2020-26137 [HIGH] CRLF injection in urllib3
CRLF injection in urllib3
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of `putrequest()`. NOTE: this is similar to CVE-2020-26116.
GHSA
CRLF injection in urllib3
ghsa·2021-06-18·CVSS 7.2
CVE-2020-26137 [HIGH] CWE-74 CRLF injection in urllib3
CRLF injection in urllib3
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of `putrequest()`. NOTE: this is similar to CVE-2020-26116.
OSV
python2.7, python3.7, python3.8 vulnerabilities
osv·2021-03-12·CVSS 7.5
CVE-2019-9674 [HIGH] python2.7, python3.7, python3.8 vulnerabilities
python2.7, python3.7, python3.8 vulnerabilities
USN-4754-1 fixed vulnerabilities in Python. This update provides
the corresponding updates for Ubuntu 18.04 and Ubuntu 20.04.
In the case of Python 2.7 for 20.04, these additional fixes are included:
It was dicovered that Python allowed remote attackers to cause a denial of
service (resource consumption) via a ZIP bomb. (CVE-2019-9674)
It was discovered that Python had potentially misleading information about
whether sorting occurs. This fix updates the documentation about it.
(CVE-2019-17514)
It was discovered that Python incorrectly handled certain TAR archives.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2019-20907)
It was discovered that Python allowed an HTTP server to conduct Regular
Expression Den
OSV
CVE-2020-26137: urllib3 before 1
osv·2020-09-30·CVSS 7.2
CVE-2020-26137 [HIGH] CVE-2020-26137: urllib3 before 1
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
OSV
CVE-2020-26116: http
osv·2020-09-27·CVSS 7.2
CVE-2020-26116 [HIGH] CVE-2020-26116: http
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
Ubuntu
Python vulnerabilities
vendor_ubuntu·2024-07-11·CVSS 7.6
CVE-2021-29921 [HIGH] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.
(CVE-2015-20107)
It was discovered that Python incorrectly used regular expressions
vulnerable to catastrophic backtracking. A remote attacker could possibly
use this issue to cause a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2018-1060, CVE-2018-1061)
It was discovered that Python failed to initialize Expat’s hash salt. A
remote attacker could possibly use this issue to cause hash collisions,
leading to a denial of service. This issue only affected Ubuntu 14.04 LTS.
(CVE-2018-14647)
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Ubuntu
Python vulnerabilities
vendor_ubuntu·2021-03-12·CVSS 7.5
CVE-2020-8492 [HIGH] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python 2.7 and Python 3.8.
USN-4754-1 fixed vulnerabilities in Python. This update provides
the corresponding updates for Ubuntu 18.04 and Ubuntu 20.04.
In the case of Python 2.7 for 20.04, these additional fixes are included:
It was dicovered that Python allowed remote attackers to cause a denial of
service (resource consumption) via a ZIP bomb. (CVE-2019-9674)
It was discovered that Python had potentially misleading information about
whether sorting occurs. This fix updates the documentation about it.
(CVE-2019-17514)
It was discovered that Python incorrectly handled certain TAR archives.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2019-20907)
It was discovered that Python
Ubuntu
Python vulnerability
vendor_ubuntu·2020-10-14
CVE-2020-26116 Python vulnerability
Title: Python vulnerability
Summary: Python could be used to perform a CRLF injection if it received a specially crafted request.
It was discovered that Python incorrectly handled certain character
sequences. A remote attacker could possibly use this issue to perform
CRLF injection.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this
vendor_msrc·2020-09-08·CVSS 6.5
CVE-2020-26137 [HIGH] CWE-74 urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is
Microsoft
http.client in Python 3.x before 3.5.10 3.6.x before 3.6.12 3.7.x before 3.7.9 and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method as demonstrated by insertin
vendor_msrc·2020-09-08·CVSS 7.2
CVE-2020-26116 [HIGH] CWE-74 http.client in Python 3.x before 3.5.10 3.6.x before 3.6.12 3.7.x before 3.7.9 and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method as demonstrated by insertin
http.client in Python 3.x before 3.5.10 3.6.x before 3.6.12 3.7.x before 3.7.9 and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more
Red Hat
python-urllib3: CRLF injection via HTTP request method
vendor_redhat·2020-02-10·CVSS 7.2
CVE-2020-26137 [HIGH] CWE-113 python-urllib3: CRLF injection via HTTP request method
python-urllib3: CRLF injection via HTTP request method
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
A flaw was found in python-urllib3. The HTTPConnection.request() does not properly validate CRLF sequences in the HTTP request method, potentially allowing manipulation of the request by injecting additional HTTP headers. The highest threat from this vulnerability is to confidentiality and integrity.
Statement: * Red Hat OpenShift Container Platform (OCP) 4 delivers the python-urllib3 package, which includes a vulnerable version of the urllib3 module, however from OCP 4.6, the python-urllib3 package is no
Red Hat
python: CRLF injection via HTTP request method in httplib/http.client
vendor_redhat·2020-02-10·CVSS 7.2
CVE-2020-26116 [HIGH] CWE-113 python: CRLF injection via HTTP request method in httplib/http.client
python: CRLF injection via HTTP request method in httplib/http.client
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
A flaw was found in Python. The built-in modules httplib and http.client (included in Python 2 and Python 3, respectively) do not properly validate CRLF sequences in the HTTP request method, potentially allowing manipulation to the request by injecting additional HTTP headers. The highest threat from this vulnerability is to confidentiality and integrity.
Statement: Versions of python36:3.6/python36 as shipped with Red Hat Enterprise Linux
Debian
CVE-2020-26137: python-urllib3 - urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP re...
vendor_debian·2020·CVSS 7.2
CVE-2020-26137 [HIGH] CVE-2020-26137: python-urllib3 - urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP re...
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
Scope: local
bookworm: resolved (fixed in 1.25.9-1)
bullseye: resolved (fixed in 1.25.9-1)
forky: resolved (fixed in 1.25.9-1)
sid: resolved (fixed in 1.25.9-1)
trixie: resolved (fixed in 1.25.9-1)
Debian
CVE-2020-26116: pypy3 - http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9...
vendor_debian·2020·CVSS 7.2
CVE-2020-26116 [HIGH] CVE-2020-26116: pypy3 - http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9...
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
Scope: local
bookworm: resolved (fixed in 7.3.3+dfsg-1)
bullseye: resolved (fixed in 7.3.3+dfsg-1)
forky: resolved (fixed in 7.3.3+dfsg-1)
sid: resolved (fixed in 7.3.3+dfsg-1)
trixie: resolved (fixed in 7.3.3+dfsg-1)
No detection rules found.
No public exploits indexed.
HackerOne
'net/http': HTTP Header Injection in the set_content_type method
hackerone·2022-02-04·CVSS 7.2
[HIGH] 'net/http': HTTP Header Injection in the set_content_type method
'net/http': HTTP Header Injection in the set_content_type method
The set\_content\_type's parameter is not filtered to prevent the injection from altering the entire request.
The vulnerable code:
```ruby
def set_content_type(type, params = {})
@header['content-type'] = [type + params.map{|k,v|"; #{k}=#{v}"}.join('')]
end
```
# PoC
1.
```ruby
require 'net/http'
uri = URI('http://127.0.0.1:8080')
req = Net::HTTP::Post.new(uri)
req.set_content_type('text/html', "charset" => "iso-8859-1\nHeader:Inject")
resp = Net::HTTP.start(uri.hostname, uri.port) do |http|
http.request(req)
end
```
2.
```
$ nc -lvp 8080
Listening on 0.0.0.0 8080
Connection received on localhost 57620
POST / HTTP/1.1
Accept-Encoding: gzip;q=1.0,deflate;q=0.6,identity;q=0.3
Accept: */*
User-Agent: Ruby
Host: 127.0.0.1:
Bugzilla
CVE-2020-26137 python-urllib3: CRLF injection via HTTP request method
bugzilla·2020-09-29·CVSS 7.2
CVE-2020-26137 [HIGH] CVE-2020-26137 python-urllib3: CRLF injection via HTTP request method
CVE-2020-26137 python-urllib3: CRLF injection via HTTP request method
A security issue was found in python-urllib3. HTTPConnection.request() does not properly validate CRLF sequences in the HTTP request method, potentially allowing to manipulate the request by injecting additional HTTP headers. Note that CVE-2020-26116 is strictly related to this bug, as the same flaw was reported in both urllib3 and built-in modules httplib/http.client.
References:
* https://bugs.python.org/issue39603
Upstream patch PR (merged upstream):
* https://github.com/urllib3/urllib3/pull/1800
Upstream commit:
* https://github.com/urllib3/urllib3/commit/1dd69c5c5982fae7c87a620d487c2ebf7a6b436b
Discussion:
Created python-pip tracking bugs for this issue:
Affects: epel-6 [bug 1883871]
Affects: fedora-all [bug
Bugzilla
CVE-2020-26116 python27: python: CRLF injection via HTTP request method in httplib/http.client [fedora-all]
bugzilla·2020-09-28·CVSS 7.2
CVE-2020-26116 [HIGH] CVE-2020-26116 python27: python: CRLF injection via HTTP request method in httplib/http.client [fedora-all]
CVE-2020-26116 python27: python: CRLF injection via HTTP request method in httplib/http.client [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
Bugzilla
CVE-2020-26116 python26: python: CRLF injection via HTTP request method in httplib/http.client [fedora-all]
bugzilla·2020-09-28·CVSS 7.2
CVE-2020-26116 [HIGH] CVE-2020-26116 python26: python: CRLF injection via HTTP request method in httplib/http.client [fedora-all]
CVE-2020-26116 python26: python: CRLF injection via HTTP request method in httplib/http.client [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
Bugzilla
CVE-2020-26116 python2: python: CRLF injection via HTTP request method in httplib/http.client [fedora-all]
bugzilla·2020-09-28·CVSS 7.2
CVE-2020-26116 [HIGH] CVE-2020-26116 python2: python: CRLF injection via HTTP request method in httplib/http.client [fedora-all]
CVE-2020-26116 python2: python: CRLF injection via HTTP request method in httplib/http.client [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affect
Bugzilla
CVE-2020-26116 python34: python: CRLF injection via HTTP request method in httplib/http.client [epel-all]
bugzilla·2020-09-28·CVSS 7.2
CVE-2020-26116 [HIGH] CVE-2020-26116 python34: python: CRLF injection via HTTP request method in httplib/http.client [epel-all]
CVE-2020-26116 python34: python: CRLF injection via HTTP request method in httplib/http.client [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
Bugzilla
CVE-2020-26116 python34: python: CRLF injection via HTTP request method in httplib/http.client [fedora-all]
bugzilla·2020-09-28·CVSS 7.2
CVE-2020-26116 [HIGH] CVE-2020-26116 python34: python: CRLF injection via HTTP request method in httplib/http.client [fedora-all]
CVE-2020-26116 python34: python: CRLF injection via HTTP request method in httplib/http.client [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
Bugzilla
CVE-2020-26116 mingw-python3: python: CRLF injection via HTTP request method in httplib/http.client [fedora-all]
bugzilla·2020-09-28·CVSS 7.2
CVE-2020-26116 [HIGH] CVE-2020-26116 mingw-python3: python: CRLF injection via HTTP request method in httplib/http.client [fedora-all]
CVE-2020-26116 mingw-python3: python: CRLF injection via HTTP request method in httplib/http.client [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2020-26116 python: CRLF injection via HTTP request method in httplib/http.client
bugzilla·2020-09-27·CVSS 7.2
CVE-2020-26116 [HIGH] CVE-2020-26116 python: CRLF injection via HTTP request method in httplib/http.client
CVE-2020-26116 python: CRLF injection via HTTP request method in httplib/http.client
A security issue was found in Python. Built-in modules httplib/http.client do not properly validate CRLF sequences in the HTTP request method, potentially allowing to manipulate the request by injecting additional HTTP headers.
Vulnerable modules:
* httplib (Python 2)
* http.client (Python 3)
References:
* https://python-security.readthedocs.io/vuln/http-header-injection-method.html
* https://bugs.python.org/issue39603
Upstream patch PR (merged upstream):
* https://github.com/python/cpython/pull/18485
Upstream commits:
* https://github.com/python/cpython/commit/8ca8a2e8fb068863c1138f07e3098478ef8be12e [master]
* https://github.com/python/cpython/commit/668d321476d974c4f51476b33aaca870272523bf [python-
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00027.htmlhttps://bugs.python.org/issue39603https://lists.debian.org/debian-lts-announce/2020/11/msg00032.htmlhttps://lists.debian.org/debian-lts-announce/2023/05/msg00024.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BW4GCLQISJCOEGQNIMVUZDQMIY6RR6CC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HDQ2THWU4GPV4Y5H5WW5PFMSWXL2CRFD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWMAVY4T4257AZHTF2RZJKNJNSJFY24O/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QOX7DGMMWWL6POCRYGAUCISOLR2IG3XV/https://python-security.readthedocs.io/vuln/http-header-injection-method.htmlhttps://security.gentoo.org/glsa/202101-18https://security.netapp.com/advisory/ntap-20201023-0001/https://usn.ubuntu.com/4581-1/https://www.oracle.com/security-alerts/cpuoct2021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-11/msg00027.htmlhttps://bugs.python.org/issue39603https://lists.debian.org/debian-lts-announce/2020/11/msg00032.htmlhttps://lists.debian.org/debian-lts-announce/2023/05/msg00024.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BW4GCLQISJCOEGQNIMVUZDQMIY6RR6CC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HDQ2THWU4GPV4Y5H5WW5PFMSWXL2CRFD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWMAVY4T4257AZHTF2RZJKNJNSJFY24O/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QOX7DGMMWWL6POCRYGAUCISOLR2IG3XV/https://python-security.readthedocs.io/vuln/http-header-injection-method.htmlhttps://security.gentoo.org/glsa/202101-18https://security.netapp.com/advisory/ntap-20201023-0001/https://usn.ubuntu.com/4581-1/https://www.oracle.com/security-alerts/cpuoct2021.html
2020-09-27
Published