ZeroHour

CVE-2020-26137

CVSS 3.1
6.5 medium
EPSS
2%p82
Published
()
Modified
Description

urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.

Vendors
pythoncanonicaldebianoracle
Products
urllib3, ubuntu linux, debian linux, communications cloud native core network function cloud native environment, zfs storage appliance kit
Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.