Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2020-26116
Description:http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
Test IDs: 1.3.6.1.4.1.25623.1.1.2.2020.2437   1.3.6.1.4.1.25623.1.1.2.2020.2318   1.3.6.1.4.1.25623.1.1.4.2020.3262.1   1.3.6.1.4.1.25623.1.0.118190   1.3.6.1.4.1.25623.1.0.878420   1.3.6.1.4.1.25623.1.1.1.2.2023.3432   1.3.6.1.4.1.25623.1.0.844652   1.3.6.1.4.1.25623.1.0.118188   1.3.6.1.4.1.25623.1.0.878623   1.3.6.1.4.1.25623.1.1.4.2021.0341.1   1.3.6.1.4.1.25623.1.0.892456   1.3.6.1.4.1.25623.1.1.4.2020.3930.1   1.3.6.1.4.1.25623.1.0.853569   1.3.6.1.4.1.25623.1.0.878540   1.3.6.1.4.1.25623.1.1.2.2020.2419   1.3.6.1.4.1.25623.1.1.4.2020.14550.1   1.3.6.1.4.1.25623.1.1.2.2020.2317   1.3.6.1.4.1.25623.1.1.4.2020.3121.1   1.3.6.1.4.1.25623.1.1.4.2021.0299.1   1.3.6.1.4.1.25623.1.1.2.2021.1449   1.3.6.1.4.1.25623.1.1.4.2020.3115.1   1.3.6.1.4.1.25623.1.0.118189   1.3.6.1.4.1.25623.1.0.878466  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2020-26116
https://security.netapp.com/advisory/ntap-20201023-0001/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BW4GCLQISJCOEGQNIMVUZDQMIY6RR6CC/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JWMAVY4T4257AZHTF2RZJKNJNSJFY24O/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QOX7DGMMWWL6POCRYGAUCISOLR2IG3XV/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HDQ2THWU4GPV4Y5H5WW5PFMSWXL2CRFD/
https://security.gentoo.org/glsa/202101-18
https://bugs.python.org/issue39603
https://bugs.python.org/issue39603
https://python-security.readthedocs.io/vuln/http-header-injection-method.html
https://python-security.readthedocs.io/vuln/http-header-injection-method.html
https://www.oracle.com/security-alerts/cpuoct2021.html
https://www.oracle.com/security-alerts/cpuoct2021.html
https://lists.debian.org/debian-lts-announce/2020/11/msg00032.html
https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html
SuSE Security Announcement: openSUSE-SU-2020:1859 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00027.html
https://usn.ubuntu.com/4581-1/




© 1998-2025 E-Soft Inc. All rights reserved.