CVE-2020-26137

NameCVE-2020-26137
Descriptionurllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
python-urllib3 (PTS)stretch1.19.1-1vulnerable
buster1.24.1-1vulnerable
bullseye, sid1.25.9-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
python-urllib3source(unstable)1.25.9-1

Notes

[buster] - python-urllib3 <no-dsa> (Minor issue)
[stretch] - python-urllib3 <no-dsa> (Minor issue)
https://bugs.python.org/issue39603
https://github.com/urllib3/urllib3/commit/1dd69c5c5982fae7c87a620d487c2ebf7a6b436b (1.25.9)
https://github.com/urllib3/urllib3/pull/1800

Search for package or bug name: Reporting problems