Skip to content

[security][ CVE-2020-26116] http.client: HTTP Header Injection in the HTTP method #83784

@maxpl0it

Description

@maxpl0it
mannequin
BPO 39603
Nosy @gvanrossum, @orsenthil, @vstinner, @larryhastings, @tiran, @ned-deily, @ambv, @miss-islington, @tirkarthi, @kmaork, @amiremohamadi, @maxpl0it
PRs
  • bpo-39603: Prevent header injection in http methods #18480
  • bpo-39603: Prevent header injection in http methods #18485
  • [3.9] bpo-39603: Prevent header injection in http methods (GH-18485) #21536
  • [3.8] bpo-39603: Prevent header injection in http methods (GH-18485) #21537
  • [3.7] bpo-39603: Prevent header injection in http methods (GH-18485) #21538
  • [3.6] bpo-39603: Prevent header injection in http methods (GH-18485) #21539
  • [3.5] bpo-39603: Prevent header injection in http methods (GH-18485) #21946
  • Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

    Show more details

    GitHub fields:

    assignee = 'https://github.com/tiran'
    closed_at = <Date 2020-07-19.09:32:11.056>
    created_at = <Date 2020-02-10.19:29:35.578>
    labels = ['type-security', 'expert-SSL', '3.8', '3.9', '3.10', '3.7', 'library']
    title = '[security][ CVE-2020-26116] http.client: HTTP Header Injection in the HTTP method'
    updated_at = <Date 2020-09-28.22:42:24.882>
    user = 'https://github.com/maxpl0it'

    bugs.python.org fields:

    activity = <Date 2020-09-28.22:42:24.882>
    actor = 'vstinner'
    assignee = 'christian.heimes'
    closed = True
    closed_date = <Date 2020-07-19.09:32:11.056>
    closer = 'ned.deily'
    components = ['Library (Lib)', 'SSL']
    creation = <Date 2020-02-10.19:29:35.578>
    creator = 'maxpl0it'
    dependencies = []
    files = []
    hgrepos = []
    issue_num = 39603
    keywords = ['patch']
    message_count = 21.0
    messages = ['361710', '361808', '361818', '361828', '361865', '361896', '362239', '373915', '373916', '373917', '373918', '373944', '373945', '373946', '374020', '374093', '374095', '376335', '377586', '377607', '377643']
    nosy_count = 14.0
    nosy_names = ['gvanrossum', 'orsenthil', 'vstinner', 'larry', 'christian.heimes', 'ned.deily', 'lukasz.langa', 'miss-islington', 'xtreak', 'kmaork', 'Amir', 'maxpl0it', 'M W2', 'mcascella']
    pr_nums = ['18480', '18485', '21536', '21537', '21538', '21539', '21946']
    priority = 'normal'
    resolution = 'fixed'
    stage = 'resolved'
    status = 'closed'
    superseder = None
    type = 'security'
    url = 'https://bugs.python.org/issue39603'
    versions = ['Python 3.5', 'Python 3.6', 'Python 3.7', 'Python 3.8', 'Python 3.9', 'Python 3.10']

    Metadata

    Metadata

    Assignees

    Labels

    3.10only security fixes3.7 (EOL)end of life3.8 (EOL)end of life3.9 (EOL)end of lifestdlibStandard Library Python modules in the Lib/ directorytopic-SSLtype-securityA security issue

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions