CVE-2020-10108: Canonical Ubuntu Linux

Critical severity, CVSS 9.8. EPSS: 4% chance of exploitation in the next 30 days.

In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 19.10 only
  • Debian Debian Linux: version 9.0 only
  • Fedoraproject Fedora: version 31 only; version 32 only
  • Oracle Solaris: version 10 only; version 11 only
  • Oracle ZFS Storage Appliance Kit: version 8.8 only
  • Twisted Twisted: up to and including 19.10.0

Published 2020-03-12. Last modified 2026-06-17.