cbcvebase.
CVE-2020-26116
published 2020-09-27

CVE-2020-26116: http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the…

high7.2CVSS 3.1
AVNACLPRNUINSCCLILAN
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianpypy3< pypy3 7.3.3+dfsg-1 (bookworm)pypy3 7.3.3+dfsg-1 (bookworm)
debianpython-urllib3< python-urllib3 1.25.9-1 (bookworm)python-urllib3 1.25.9-1 (bookworm)
debianpython2.7< pypy3 7.3.3+dfsg-1 (bookworm)pypy3 7.3.3+dfsg-1 (bookworm)
debianpython3.9< pypy3 7.3.3+dfsg-1 (bookworm)pypy3 7.3.3+dfsg-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
msrccbl2_python-virtualenv_20.26.6-1_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_python-urllib3_1.25.9-2_on_cbl_mariner_1.0
msrccm1_python3_3.7.10-3_on_cbl_mariner_1.0
opensuseleap
oraclecommunications_cloud_native_core_network_function_cloud_native_environment
oraclezfs_storage_appliance_kit
pythonpython>= 3.0.0 < 3.5.103.5.10
pythonpython>= 3.6.0 < 3.6.123.6.12
pythonpython>= 3.7.0 < 3.7.93.7.9
pythonpython>= 3.8.0 < 3.8.53.8.5

CVSS provenance

nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
ghsa7.2HIGH
osv7.6HIGH