Description
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2686-1 | python-urllib3 security update |
Debian DLA |
DLA-3610-1 | python-urllib3 security update |
EUVD |
EUVD-2020-0230 | urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116. |
Github GHSA |
GHSA-wqvq-5m8c-6g24 | CRLF injection in urllib3 |
Ubuntu USN |
USN-4570-1 | urllib3 vulnerability |
References
History
No history.
Subscriptions
Canonical
Subscribe
Ubuntu Linux
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Oracle
Subscribe
Communications Cloud Native Core Network Function Cloud Native Environment
Subscribe
Zfs Storage Appliance Kit
Subscribe
Python
Subscribe
Urllib3
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Openshift
Subscribe
Rhel Software Collections
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T15:49:07.138Z
Reserved: 2020-09-29T00:00:00.000Z
Link: CVE-2020-26137
No data.
Status : Modified
Published: 2020-09-30T18:15:26.773
Modified: 2024-11-21T05:19:19.680
Link: CVE-2020-26137
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA
Ubuntu USN