---
id: CVE-2020-26116
title: >-
  http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before
  3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls
  the HTTP request method, as demonstrated by inserting CR and LF control
  characters in…
summary: >-
  http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before
  3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls
  the HTTP request method, as demonstrated by inserting CR and LF control
  characters in…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-74
vendor: python
product: python
affected:
  - 'python >= 3.0.0, < 3.5.10'
  - 'python >= 3.6.0, < 3.6.12'
  - 'python >= 3.7.0, < 3.7.9'
  - 'python >= 3.8.0, < 3.8.5'
  - fedora = 31
  - fedora = 32
  - fedora = 33
  - ubuntu_linux = 12.04
  - ubuntu_linux = 14.04
  - ubuntu_linux = 16.04
  - ubuntu_linux = 18.04
  - solidfire
  - hci_storage_node
  - debian_linux = 9.0
  - zfs_storage_appliance_kit = 8.8
  - leap = 15.1
patched:
  - python 3.8.5
published: '2020-09-27'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:26.807'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-26116'
references:
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00027.html'
    label: cve@mitre.org
  - url: 'https://bugs.python.org/issue39603'
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2020/11/msg00032.html'
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html'
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BW4GCLQISJCOEGQNIMVUZDQMIY6RR6CC/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HDQ2THWU4GPV4Y5H5WW5PFMSWXL2CRFD/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWMAVY4T4257AZHTF2RZJKNJNSJFY24O/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QOX7DGMMWWL6POCRYGAUCISOLR2IG3XV/
    label: cve@mitre.org
  - url: >-
      https://python-security.readthedocs.io/vuln/http-header-injection-method.html
    label: cve@mitre.org
  - url: 'https://security.gentoo.org/glsa/202101-18'
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20201023-0001/'
    label: cve@mitre.org
  - url: 'https://usn.ubuntu.com/4581-1/'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00027.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugs.python.org/issue39603'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2020/11/msg00032.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BW4GCLQISJCOEGQNIMVUZDQMIY6RR6CC/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HDQ2THWU4GPV4Y5H5WW5PFMSWXL2CRFD/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWMAVY4T4257AZHTF2RZJKNJNSJFY24O/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QOX7DGMMWWL6POCRYGAUCISOLR2IG3XV/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://python-security.readthedocs.io/vuln/http-header-injection-method.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202101-18'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20201023-0001/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4581-1/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.06358
epssPercentile: 0.93469
ingestedAt: '2026-10-08T22:11:53.721Z'
---

## Overview

http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.

## Affected

- `python >= 3.0.0, < 3.5.10`
- `python >= 3.6.0, < 3.6.12`
- `python >= 3.7.0, < 3.7.9`
- `python >= 3.8.0, < 3.8.5`
- `fedora = 31`
- `fedora = 32`
- `fedora = 33`
- `ubuntu_linux = 12.04`
- `ubuntu_linux = 14.04`
- `ubuntu_linux = 16.04`
- `ubuntu_linux = 18.04`
- `solidfire`
- `hci_storage_node`
- `debian_linux = 9.0`
- `zfs_storage_appliance_kit = 8.8`
- `leap = 15.1`

## Remediation

Upgrade past the affected range:

- `python 3.8.5`
