python-twisted: HTTP request smuggling when presented with two Content-Length headers
Published Mar 12, 2020
9.3
CRITICALCVSS 4.0
EPSS 3.97%
Description
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.
Affected products
No data.
Configuration 2
- 31
- 32
Configuration 3
- 9.0
Configuration 4
- 14.04
- 16.04
- 18.04
- 19.10
No data.
Red Hat Enterprise Linux 6
python-twisted-web-0:8.2.0-6.el6_10
Fixed · RHSA-2020:1962
Red Hat Enterprise Linux 7
python-twisted-web-0:12.1.0-7.el7_8
Fixed · RHSA-2020:1561
Red Hat Ceph Storage 2
calamari-server
Will not fix
Red Hat OpenShift Container Platform 4
python-twisted
Will not fix
Red Hat OpenStack Platform 10 (Newton)
python-twisted
Will not fix
Red Hat OpenStack Platform 13 (Queens)
python-twisted
Will not fix
Red Hat OpenStack Platform 16 (Train)
python-twisted
Will not fix
Red Hat Satellite 6
python-twisted
Will not fix
Red Hat Satellite 6
python-twisted-web
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | python-twisted-web-0:8.2.0-6.el6_10 | Fixed | RHSA-2020:1962 |
| Red Hat Enterprise Linux 7 | python-twisted-web-0:12.1.0-7.el7_8 | Fixed | RHSA-2020:1561 |
| Red Hat Ceph Storage 2 | calamari-server | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | python-twisted | Will not fix | n/a |
| Red Hat OpenStack Platform 10 (Newton) | python-twisted | Will not fix | n/a |
| Red Hat OpenStack Platform 13 (Queens) | python-twisted | Will not fix | n/a |
| Red Hat OpenStack Platform 16 (Train) | python-twisted | Will not fix | n/a |
| Red Hat Satellite 6 | python-twisted | Will not fix | n/a |
| Red Hat Satellite 6 | python-twisted-web | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
OpenShift Container Platform 4.3 and later includes `python-twisted` as a dependency of `python-prometheus_client` in Ironic container images, however the affected code is not used. Red Hat OpenStack Platform packages the flawed code, however python-twisted's web.HTTP functionality is not used in the RHOSP environment. For this reason, the RHOSP impact has been lowered to moderate and no update will be provided at this time for the RHOSP python-twisted package. Red Hat Satellite uses affected versions of `python-twisted` and `python-twisted-web` modules in Pulp, however, it is not vulnerable since `http` modal of web implementation is not expose in product. Red Hat Satellite may update `python-twisted` and `python-twisted-web` in future. This issue affects the version of python-twisted(embedded in calamari-server) shipped with Red Hat Ceph Storage 2. However, calamari is no longer supported, hence the embedded python-twisted package will not be fixed.
Red Hat mitigation
When python-twisted-web is used as the back-end of your infrastructure, you can partially mitigate the problem by ensuring that each request on the front-end component (e.g. proxy) is sent over a separate network connection to the python-twisted-web server. This will prevent interference between different users, but it will not prevent all possible attacks that can be performed, which would vary based on the infrastructure and application in use.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (31 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.97% (0.03973) | 90.15th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.08% (0.04083) | 89.37th | v5 (v2026.06.15) |
| May 30, 2026 | 2.32% (0.02324) | 85.08th | v4 (v2025.03.14) |
| Dec 28, 2025 | 3.41% (0.03411) | 87.06th | v4 (v2025.03.14) |
| Dec 27, 2025 | 5.04% (0.05037) | 89.45th | v4 (v2025.03.14) |
| Nov 30, 2025 | 3.41% (0.03411) | 87.01th | v4 (v2025.03.14) |
| Nov 22, 2025 | 2.23% (0.02233) | 84.02th | v4 (v2025.03.14) |
| Nov 21, 2025 | 3.28% (0.03279) | 86.70th | v4 (v2025.03.14) |
| Nov 18, 2025 | 4.80% (0.04799) | 88.41th | v4 (v2025.03.14) |
| Oct 28, 2025 | 3.72% (0.03716) | 87.44th | v4 (v2025.03.14) |
| Oct 27, 2025 | 5.48% (0.05476) | 89.78th | v4 (v2025.03.14) |
| Oct 1, 2025 | 3.72% (0.03716) | 87.53th | v4 (v2025.03.14) |
| Jun 15, 2025 | 4.95% (0.04950) | 89.13th | v4 (v2025.03.14) |
| Mar 30, 2025 | 1.06% (0.01059) | 75.64th | v4 (v2025.03.14) |
| Mar 29, 2025 | 6.53% (0.06530) | 84.79th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.15% (0.01150) | 77.02th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.93% (0.00934) | 83.71th | v3 (v2023.03.01) |
| Jul 6, 2024 | 0.93% (0.00934) | 83.15th | v3 (v2023.03.01) |
| Feb 17, 2024 | 0.95% (0.00947) | 82.65th | v3 (v2023.03.01) |
| Feb 1, 2024 | 0.83% (0.00830) | 80.19th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.86% (0.00864) | 80.39th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.61% (0.00610) | 75.35th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.54% (0.01537) | 74.52th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.54% (0.01537) | 74.48th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.54% (0.01537) | 72.41th | v2 (v2022.01.01) |
| Feb 20, 2022 | 20.27% (0.20271) | 94.07th | v2 (v2022.01.01) |
| Feb 4, 2022 | 23.64% (0.23638) | 94.79th | v2 (v2022.01.01) |
| Feb 3, 2022 | 8.31% (0.08307) | 85.36th | v1 |
| Jan 6, 2022 | 8.31% (0.08307) | 85.19th | v1 |
| Sep 1, 2021 | 1.98% (0.01979) | 76.71th | v1 |
| Apr 14, 2021 | 1.98% (0.01979) | 0.00th | v1 |
References (20)
- https://access.redhat.com/security/cve/CVE-2020-10108 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1813439 Issue Tracking
- https://github.com/advisories/GHSA-h96w-mmrf-2h6v Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/twisted/PYSEC-2020-259.yaml
- https://github.com/twisted/twisted/blob/6ff2c40e42416c83203422ff70dfc49d2681c8e2/NEWS.rst#twisted-2030-2020-03-13
- https://github.com/twisted/twisted/blob/twisted-20.3.0/NEWS.rst
- https://github.com/twisted/twisted/commit/4a7d22e490bb8ff836892cc99a1f54b85ccb0281
- https://know.bishopfox.com/advisories x_refsource_MISCExploitThird Party Advisory
- https://know.bishopfox.com/advisories/twisted-version-19.10.0 x_refsource_MISCRelease NotesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/02/msg00021.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6ISMZFZBWW4EV6ETJGXAYIXN3AT7GBPL vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YW3NIL7VXSGJND2Q4BSXM3CFTAFU6T7D vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6ISMZFZBWW4EV6ETJGXAYIXN3AT7GBPL
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YW3NIL7VXSGJND2Q4BSXM3CFTAFU6T7D
- https://nvd.nist.gov/vuln/detail/CVE-2020-10108
- https://security.gentoo.org/glsa/202007-24 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://usn.ubuntu.com/4308-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4308-2 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-10108
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.