CVE-2020-26137

CWE-74CWE-11316 documents9 sources
Severity
6.5MEDIUM
EPSS
0.3%
top 48.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 30
Latest updateJun 18

Description

urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 3.9 | Impact: 2.5

Affected Packages5 packages

Also affects: Debian Linux 9.0, Ubuntu Linux 16.04, 18.04, 20.04

Patches

🔴Vulnerability Details

4
OSV
CRLF injection in urllib32021-06-18
GHSA
CRLF injection in urllib32021-06-18
OSV
CVE-2020-26137: urllib3 before 12020-09-30
CVEList
CVE-2020-26137: urllib3 before 12020-09-29

📋Vendor Advisories

4
Ubuntu
urllib3 vulnerability2020-10-05
Microsoft
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this2020-09-08
Red Hat
python-urllib3: CRLF injection via HTTP request method2020-02-10
Debian
CVE-2020-26137: python-urllib3 - urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP re...2020

💬Community

7
Bugzilla
CVE-2020-26137 python-urllib3: CRLF injection via HTTP request method [openstack-rdo]2020-10-11
Bugzilla
CVE-2020-26137 python3-urllib3: python-urllib3: CRLF injection via HTTP request method [epel-all]2020-09-30
Bugzilla
CVE-2020-26137 python-pip: python-urllib3: CRLF injection via HTTP request method [fedora-all]2020-09-30
Bugzilla
CVE-2020-26137 python-pip-epel: python-urllib3: CRLF injection via HTTP request method [epel-7]2020-09-30
Bugzilla
CVE-2020-26137 python-urllib3: CRLF injection via HTTP request method [fedora-all]2020-09-30
CVE-2020-26137 (MEDIUM CVSS 6.5) | urllib3 before 1.25.9 allows CRLF i | cvebase.io