CVE-2020-26137
published 2020-09-30CVE-2020-26137: urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the…
PriorityP335medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
2.27%
81.1th percentile
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | python-urllib3 | < python-urllib3 1.25.9-1 (bookworm) | python-urllib3 1.25.9-1 (bookworm) |
| msrc | cbl2_python-virtualenv_20.26.6-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_python-urllib3_1.25.9-2_on_cbl_mariner_1.0 | — | — |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
| python | urllib3 | < 1.25.9 | 1.25.9 |
| urllib3 | urllib3 | >= 0 < 1.25.9 | 1.25.9 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
ghsa7.2HIGH
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
vendor_msrc6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
urllib3 vulnerability
vendor_ubuntu·2020-10-05
CVE-2020-26137 urllib3 vulnerability
Title: urllib3 vulnerability
Summary: urllib3 could be used to perform a CRLF injection if it received a
specially crafted request.
It was discovered that urllib3 incorrectly handled certain character
sequences. A remote attacker could possibly use this issue to perform CRLF
injection.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this
vendor_msrc·2020-09-08·CVSS 6.5
CVE-2020-26137 [HIGH] CWE-74 urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is
Red Hat
python-urllib3: CRLF injection via HTTP request method
vendor_redhat·2020-02-10·CVSS 7.2
CVE-2020-26137 [HIGH] CWE-113 python-urllib3: CRLF injection via HTTP request method
python-urllib3: CRLF injection via HTTP request method
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
A flaw was found in python-urllib3. The HTTPConnection.request() does not properly validate CRLF sequences in the HTTP request method, potentially allowing manipulation of the request by injecting additional HTTP headers. The highest threat from this vulnerability is to confidentiality and integrity.
Statement: * Red Hat OpenShift Container Platform (OCP) 4 delivers the python-urllib3 package, which includes a vulnerable version of the urllib3 module, however from OCP 4.6, the python-urllib3 package is no
Debian
CVE-2020-26137: python-urllib3 - urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP re...
vendor_debian·2020·CVSS 7.2
CVE-2020-26137 [HIGH] CVE-2020-26137: python-urllib3 - urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP re...
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
Scope: local
bookworm: resolved (fixed in 1.25.9-1)
bullseye: resolved (fixed in 1.25.9-1)
forky: resolved (fixed in 1.25.9-1)
sid: resolved (fixed in 1.25.9-1)
trixie: resolved (fixed in 1.25.9-1)
OSV
CRLF injection in urllib3
osv·2021-06-18·CVSS 7.2
CVE-2020-26137 [HIGH] CRLF injection in urllib3
CRLF injection in urllib3
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of `putrequest()`. NOTE: this is similar to CVE-2020-26116.
GHSA
CRLF injection in urllib3
ghsa·2021-06-18·CVSS 7.2
CVE-2020-26137 [HIGH] CWE-74 CRLF injection in urllib3
CRLF injection in urllib3
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of `putrequest()`. NOTE: this is similar to CVE-2020-26116.
OSV
CVE-2020-26137: urllib3 before 1
osv·2020-09-30·CVSS 7.2
CVE-2020-26137 [HIGH] CVE-2020-26137: urllib3 before 1
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-26137 python-urllib3: CRLF injection via HTTP request method [openstack-rdo]
bugzilla·2020-10-11·CVSS 6.5
CVE-2020-26137 [MEDIUM] CVE-2020-26137 python-urllib3: CRLF injection via HTTP request method [openstack-rdo]
CVE-2020-26137 python-urllib3: CRLF injection via HTTP request method [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
RDO does not ship python-url
Bugzilla
CVE-2020-26137 python3-urllib3: python-urllib3: CRLF injection via HTTP request method [epel-all]
bugzilla·2020-09-30·CVSS 6.5
CVE-2020-26137 [MEDIUM] CVE-2020-26137 python3-urllib3: python-urllib3: CRLF injection via HTTP request method [epel-all]
CVE-2020-26137 python3-urllib3: python-urllib3: CRLF injection via HTTP request method [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2020-26137 python-pip: python-urllib3: CRLF injection via HTTP request method [fedora-all]
bugzilla·2020-09-30·CVSS 6.5
CVE-2020-26137 [MEDIUM] CVE-2020-26137 python-pip: python-urllib3: CRLF injection via HTTP request method [fedora-all]
CVE-2020-26137 python-pip: python-urllib3: CRLF injection via HTTP request method [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple s
Bugzilla
CVE-2020-26137 python-pip-epel: python-urllib3: CRLF injection via HTTP request method [epel-7]
bugzilla·2020-09-30·CVSS 6.5
CVE-2020-26137 [MEDIUM] CVE-2020-26137 python-pip-epel: python-urllib3: CRLF injection via HTTP request method [epel-7]
CVE-2020-26137 python-pip-epel: python-urllib3: CRLF injection via HTTP request method [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following templat
Bugzilla
CVE-2020-26137 python-urllib3: CRLF injection via HTTP request method [fedora-all]
bugzilla·2020-09-30·CVSS 6.5
CVE-2020-26137 [MEDIUM] CVE-2020-26137 python-urllib3: CRLF injection via HTTP request method [fedora-all]
CVE-2020-26137 python-urllib3: CRLF injection via HTTP request method [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ver
Bugzilla
CVE-2020-26137 python-pip: python-urllib3: CRLF injection via HTTP request method [epel-6]
bugzilla·2020-09-30·CVSS 6.5
CVE-2020-26137 [MEDIUM] CVE-2020-26137 python-pip: python-urllib3: CRLF injection via HTTP request method [epel-6]
CVE-2020-26137 python-pip: python-urllib3: CRLF injection via HTTP request method [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to
Bugzilla
CVE-2020-26137 python-urllib3: CRLF injection via HTTP request method
bugzilla·2020-09-29·CVSS 7.2
CVE-2020-26137 [HIGH] CVE-2020-26137 python-urllib3: CRLF injection via HTTP request method
CVE-2020-26137 python-urllib3: CRLF injection via HTTP request method
A security issue was found in python-urllib3. HTTPConnection.request() does not properly validate CRLF sequences in the HTTP request method, potentially allowing to manipulate the request by injecting additional HTTP headers. Note that CVE-2020-26116 is strictly related to this bug, as the same flaw was reported in both urllib3 and built-in modules httplib/http.client.
References:
* https://bugs.python.org/issue39603
Upstream patch PR (merged upstream):
* https://github.com/urllib3/urllib3/pull/1800
Upstream commit:
* https://github.com/urllib3/urllib3/commit/1dd69c5c5982fae7c87a620d487c2ebf7a6b436b
Discussion:
Created python-pip tracking bugs for this issue:
Affects: epel-6 [bug 1883871]
Affects: fedora-all [bug
https://bugs.python.org/issue39603https://github.com/urllib3/urllib3/commit/1dd69c5c5982fae7c87a620d487c2ebf7a6b436bhttps://github.com/urllib3/urllib3/pull/1800https://lists.debian.org/debian-lts-announce/2021/06/msg00015.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00012.htmlhttps://usn.ubuntu.com/4570-1/https://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://bugs.python.org/issue39603https://github.com/urllib3/urllib3/commit/1dd69c5c5982fae7c87a620d487c2ebf7a6b436bhttps://github.com/urllib3/urllib3/pull/1800https://lists.debian.org/debian-lts-announce/2021/06/msg00015.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00012.htmlhttps://usn.ubuntu.com/4570-1/https://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2020-09-30
Published