Back

CVE-2020-10109

CRITICAL

In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request body was interpreted as a pipelined request.

Published: Mar 12, 2020 Modified: Jun 17, 2026
CWE-444

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (8)

Vendor Product Version
twisted twisted *
fedoraproject fedora 31
fedoraproject fedora 32
debian debian_linux 9.0
canonical ubuntu_linux 14.04
canonical ubuntu_linux 16.04
canonical ubuntu_linux 18.04
canonical ubuntu_linux 19.10

GitHub Security Advisory GHSA-p5xh-vx83-mxcj

HTTP Request Smuggling in Twisted

pip Twisted < 20.3.0 Fixed: 20.3.0

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 3.29%

Top 12% most likely to be exploited

Threat Score 40.2 / 100

Data Sources

NVD EPSS GitHub