CVE-2020-26116

🟡 Monitoruj

Wstrzyknięcie CRLF w http.client w Pythonie umożliwia manipulację nagłówkami HTTP.

CVSS
7.2
EPSS
6.4%
Exploit
poc
Vendor
canonical
Opis źródłowy (NVD)

http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.

exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.2
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)6.4%
Opublikowano (NVD)2020-09-27 04:15:11 UTC
Ostatnia modyfikacja (NVD)2026-10-08 21:17:26 UTC
Referencje