CVE-2020-26116: Canonical Ubuntu Linux
High severity, CVSS 7.2. EPSS: 6.4% chance of exploitation in the next 30 days.
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only
- Debian Debian Linux: version 9.0 only
- Fedoraproject Fedora: version 31 only; version 32 only; version 33 only
- Netapp Hci Storage Node: affected versions not specified
- Netapp Solidfire: affected versions not specified
- Opensuse Leap: version 15.1 only
- Oracle ZFS Storage Appliance Kit: version 8.8 only
- Python Python: from 3.0.0, before 3.5.10 (fixed in 3.5.10); from 3.6.0, before 3.6.12 (fixed in 3.6.12); from 3.7.0, before 3.7.9 (fixed in 3.7.9); from 3.8.0, before 3.8.5 (fixed in 3.8.5)
Published 2020-09-27. Last modified 2026-10-08.