Back
CVE-2020-10108
CRITICAL
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.
Published: Mar 12, 2020
Modified: Jun 17, 2026
CWE-444
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (11)
| Vendor | Product | Version |
|---|---|---|
| twisted | twisted | * |
| fedoraproject | fedora | 31 |
| fedoraproject | fedora | 32 |
| debian | debian_linux | 9.0 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 19.10 |
| oracle | zfs_storage_appliance_kit | 8.8 |
| oracle | solaris | 10 |
| oracle | solaris | 11 |
GitHub Security Advisory GHSA-h96w-mmrf-2h6v
Improper Input Validation in Twisted
pip
Twisted
< 20.3.0
Fixed: 20.3.0
References (18)
- https://know.bishopfox.com/advisories Exploit, Third Party Advisory
- https://know.bishopfox.com/advisories/twisted-version-19.10.0 Release Notes, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/02/msg00021.html Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6ISMZFZBWW4EV6ETJGXAYIXN3AT7GBPL/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YW3NIL7VXSGJND2Q4BSXM3CFTAFU6T7D/
- https://security.gentoo.org/glsa/202007-24 Third Party Advisory
- https://usn.ubuntu.com/4308-1/ Third Party Advisory
- https://usn.ubuntu.com/4308-2/ Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html Patch, Third Party Advisory
- https://know.bishopfox.com/advisories Exploit, Third Party Advisory
- https://know.bishopfox.com/advisories/twisted-version-19.10.0 Release Notes, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/02/msg00021.html Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6ISMZFZBWW4EV6ETJGXAYIXN3AT7GBPL/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YW3NIL7VXSGJND2Q4BSXM3CFTAFU6T7D/
- https://security.gentoo.org/glsa/202007-24 Third Party Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
3.97%
Top 10% most likely to be exploited
Threat Score
40.4 / 100
Data Sources
NVD
EPSS
GitHub