CVE-2020-26116

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-26116
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-26116.json
Aliases
Related
Published
2020-09-27T04:15:11Z
Modified
2023-12-06T01:00:26.913859Z
Details

http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.

References

Affected packages

Git / github.com/python/cpython

Affected versions

v3.*

v3.8.0
v3.8.1
v3.8.1rc1
v3.8.2
v3.8.2rc1
v3.8.2rc2
v3.8.3
v3.8.3rc1
v3.8.4
v3.8.4rc1