CVE-2020-26137: Canonical Ubuntu Linux

Medium severity, CVSS 6.5. EPSS: 2.3% chance of exploitation in the next 30 days.

urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 20.04 only
  • Debian Debian Linux: version 9.0 only
  • Oracle Communications Cloud Native Core Network Function Cloud Native Environment: version 22.2.0 only
  • Oracle ZFS Storage Appliance Kit: version 8.8 only
  • Python URLLIB3: before 1.25.9 (fixed in 1.25.9)

Published 2020-09-30. Last modified 2026-06-17.