CVE-2020-11078: Debian Linux
Medium severity, CVSS 6.8. EPSS: 2.4% chance of exploitation in the next 30 days.
In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden requests to same server. This vulnerability impacts software that uses httplib2 with uri constructed by string concatenation, as opposed to proper urllib building with escaping. This has been fixed in 0.18.0.
Affected products
- Debian Debian Linux: version 8.0 only
- Fedoraproject Fedora: version 31 only; version 32 only
- HTTPLIB2 Project HTTPLIB2: before 0.18.0 (fixed in 0.18.0)
Published 2020-05-20. Last modified 2026-06-17.