Back

CVE-2020-10108

CRITICAL

In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.

Published: Mar 12, 2020 Modified: Jun 17, 2026
CWE-444

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (11)

Vendor Product Version
twisted twisted *
fedoraproject fedora 31
fedoraproject fedora 32
debian debian_linux 9.0
canonical ubuntu_linux 14.04
canonical ubuntu_linux 16.04
canonical ubuntu_linux 18.04
canonical ubuntu_linux 19.10
oracle zfs_storage_appliance_kit 8.8
oracle solaris 10
oracle solaris 11

GitHub Security Advisory GHSA-h96w-mmrf-2h6v

Improper Input Validation in Twisted

pip Twisted < 20.3.0 Fixed: 20.3.0

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 3.97%

Top 10% most likely to be exploited

Threat Score 40.4 / 100

Data Sources

NVD EPSS GitHub