CVE-2020-10108: Canonical Ubuntu Linux
Critical severity, CVSS 9.8. EPSS: 4% chance of exploitation in the next 30 days.
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 19.10 only
- Debian Debian Linux: version 9.0 only
- Fedoraproject Fedora: version 31 only; version 32 only
- Oracle Solaris: version 10 only; version 11 only
- Oracle ZFS Storage Appliance Kit: version 8.8 only
- Twisted Twisted: up to and including 19.10.0
Published 2020-03-12. Last modified 2026-06-17.