PT-2020-6483 · Urllib3+9 · Urllib3+9

Published

2020-02-10

·

Updated

2026-06-03

·

CVE-2020-26137

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions urllib3 versions prior to 1.25.9
Description The issue is related to insufficient neutralization of special elements in the HTTP request method, which can lead to CRLF injection if the attacker controls the HTTP request method. This can be demonstrated by inserting CR and LF control characters in the first argument of putrequest(). The exploitation of this issue may allow a remote attacker to access and compromise confidential data.
Recommendations For versions prior to 1.25.9, update to version 1.25.9 or later to resolve the issue. As a temporary workaround, consider restricting the use of the putrequest() function to minimize the risk of exploitation.

Fix

DoS

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:1631
ALSA-2021:1761
ALT-PU-2023-7180
BDU:2021-05230
CESA-2021_1631
CESA-2021_1761
CESA-2022_5235
CLEANSTART-2026-SV37938
CVE-2020-26137
DLA-2686-1
DLA-3610-1
GHSA-WQVQ-5M8C-6G24
MGASA-2021-0054
MGASA-2021-0055
OPENSUSE-SU-2020:2237-1
OPENSUSE-SU-2020:2282-1
OPENSUSE-SU-2020_2237-1
OPENSUSE-SU-2020_2282-1
OPENSUSE-SU-2021:1206-1
OPENSUSE-SU-2021:2817-1
OPENSUSE-SU-2021_1206-1
OPENSUSE-SU-2021_2817-1
OPENSUSE-SU-2024:13212-1
OPENSUSE-SU-2024:13213-1
PYSEC-2020-148
RHSA-2020:4299
RHSA-2021:0034
RHSA-2021:0079
RHSA-2021:1631
RHSA-2021:1761
RHSA-2021_1631
RHSA-2021_1761
RHSA-2022:5235
RHSA-2022_5235
RLSA-2021:1631
RLSA-2021:1761
ROSA-SA-2023-2203
SUSE-FU-2022:0444-1
SUSE-FU-2022:0445-1
SUSE-SU-2020:3309-1
SUSE-SU-2020:3624-1
SUSE-SU-2020:3723-1
SUSE-SU-2020:3897-1
SUSE-SU-2020_3723-1
SUSE-SU-2021:2817-1
SUSE-SU-2021:3251-1
SUSE-SU-2021_2817-1
SUSE-SU-2021_3251-1
USN-4570-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
Urllib3