{"id":"CVE-2020-26116","title":"http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in…","summary":"http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in…","severity":"high","cvss":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","cwe":["CWE-74"],"vendor":"python","product":"python","affected":["python >= 3.0.0, < 3.5.10","python >= 3.6.0, < 3.6.12","python >= 3.7.0, < 3.7.9","python >= 3.8.0, < 3.8.5","fedora = 31","fedora = 32","fedora = 33","ubuntu_linux = 12.04","ubuntu_linux = 14.04","ubuntu_linux = 16.04","ubuntu_linux = 18.04","solidfire","hci_storage_node","debian_linux = 9.0","zfs_storage_appliance_kit = 8.8","leap = 15.1"],"patched":["python 3.8.5"],"published":"2020-09-27","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:17:26.807","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-26116","references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00027.html","label":"cve@mitre.org"},{"url":"https://bugs.python.org/issue39603","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2020/11/msg00032.html","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BW4GCLQISJCOEGQNIMVUZDQMIY6RR6CC/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HDQ2THWU4GPV4Y5H5WW5PFMSWXL2CRFD/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWMAVY4T4257AZHTF2RZJKNJNSJFY24O/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QOX7DGMMWWL6POCRYGAUCISOLR2IG3XV/","label":"cve@mitre.org"},{"url":"https://python-security.readthedocs.io/vuln/http-header-injection-method.html","label":"cve@mitre.org"},{"url":"https://security.gentoo.org/glsa/202101-18","label":"cve@mitre.org"},{"url":"https://security.netapp.com/advisory/ntap-20201023-0001/","label":"cve@mitre.org"},{"url":"https://usn.ubuntu.com/4581-1/","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00027.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugs.python.org/issue39603","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2020/11/msg00032.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BW4GCLQISJCOEGQNIMVUZDQMIY6RR6CC/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HDQ2THWU4GPV4Y5H5WW5PFMSWXL2CRFD/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWMAVY4T4257AZHTF2RZJKNJNSJFY24O/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QOX7DGMMWWL6POCRYGAUCISOLR2IG3XV/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://python-security.readthedocs.io/vuln/http-header-injection-method.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202101-18","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20201023-0001/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4581-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.06358,"epssPercentile":0.93469,"ingestedAt":"2026-10-08T22:11:53.721Z","slug":"CVE-2020-26116","body":"## Overview\n\nhttp.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.\n\n## Affected\n\n- `python >= 3.0.0, < 3.5.10`\n- `python >= 3.6.0, < 3.6.12`\n- `python >= 3.7.0, < 3.7.9`\n- `python >= 3.8.0, < 3.8.5`\n- `fedora = 31`\n- `fedora = 32`\n- `fedora = 33`\n- `ubuntu_linux = 12.04`\n- `ubuntu_linux = 14.04`\n- `ubuntu_linux = 16.04`\n- `ubuntu_linux = 18.04`\n- `solidfire`\n- `hci_storage_node`\n- `debian_linux = 9.0`\n- `zfs_storage_appliance_kit = 8.8`\n- `leap = 15.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `python 3.8.5`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":39.6,"likelihood":1.3,"exploitation":0,"ransomware":0},"changes":[]}