python-twisted: HTTP request smuggling when presented with a Content-Length and a chunked Transfer-Encoding header
Published Mar 12, 2020
9.3
CRITICALCVSS 4.0
EPSS 3.29%
Description
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request body was interpreted as a pipelined request.
Affected products
No data.
Configuration 2
- 31
- 32
Configuration 3
- 9.0
Configuration 4
- 14.04
- 16.04
- 18.04
- 19.10
No data.
Red Hat Enterprise Linux 7
python-twisted-web-0:12.1.0-7.el7_8
Fixed · RHSA-2020:1561
Red Hat Ceph Storage 2
calamari-server
Will not fix
Red Hat Enterprise Linux 6
python-twisted-web
Not affected
Red Hat OpenShift Container Platform 4
python-twisted
Will not fix
Red Hat OpenStack Platform 10 (Newton)
python-twisted
Out of support scope
Red Hat OpenStack Platform 13 (Queens)
python-twisted
Will not fix
Red Hat OpenStack Platform 16 (Train)
python-twisted
Will not fix
Red Hat Satellite 6
python-twisted
Will not fix
Red Hat Satellite 6
python-twisted-web
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | python-twisted-web-0:12.1.0-7.el7_8 | Fixed | RHSA-2020:1561 |
| Red Hat Ceph Storage 2 | calamari-server | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | python-twisted-web | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | python-twisted | Will not fix | n/a |
| Red Hat OpenStack Platform 10 (Newton) | python-twisted | Out of support scope | n/a |
| Red Hat OpenStack Platform 13 (Queens) | python-twisted | Will not fix | n/a |
| Red Hat OpenStack Platform 16 (Train) | python-twisted | Will not fix | n/a |
| Red Hat Satellite 6 | python-twisted | Will not fix | n/a |
| Red Hat Satellite 6 | python-twisted-web | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Although Red Hat OpenStack Platform packages the flawed code, python-twisted's web.HTTP functionality is not used in the RHOSP environment. For this reason, the RHOSP impact has been lowered to moderate and no update will be provided at this time for the RHOSP python-twisted package . OpenShift Container Platform 4.3 and later includes `python-twisted` as a dependency of `python-prometheus_client` in Ironic container images, however the affected code is not used. Red Hat Satellite uses affected versions of `python-twisted` and `python-twisted-web` modules in Pulp, however, it is not vulnerable since `http` modal of web implementation is not expose in product. Red Hat Satellite may update `python-twisted` and `python-twisted-web` in future. This issue affects the version of python-twisted(embedded in calamari-server) shipped with Red Hat Ceph Storage 2. However, calamari is no longer supported, hence the embedded python-twisted package will not be fixed.
Red Hat mitigation
When python-twisted-web is used as the back-end of your infrastructure, you can partially mitigate the problem by ensuring that each request on the front-end component (e.g. proxy) is sent over a separate network connection to the python-twisted-web server. This will prevent interference between different users, but it will not prevent all possible attacks that can be performed, which would vary based on the infrastructure and application in use.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (26 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.29% (0.03289) | 88.07th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.30% (0.03298) | 86.87th | v5 (v2026.06.15) |
| May 30, 2026 | 2.33% (0.02327) | 85.09th | v4 (v2025.03.14) |
| Nov 30, 2025 | 3.52% (0.03518) | 87.21th | v4 (v2025.03.14) |
| Nov 21, 2025 | 2.23% (0.02235) | 84.02th | v4 (v2025.03.14) |
| Nov 18, 2025 | 3.56% (0.03565) | 86.53th | v4 (v2025.03.14) |
| Sep 13, 2025 | 2.01% (0.02009) | 83.01th | v4 (v2025.03.14) |
| Jun 15, 2025 | 3.69% (0.03692) | 87.38th | v4 (v2025.03.14) |
| Mar 30, 2025 | 0.57% (0.00574) | 66.15th | v4 (v2025.03.14) |
| Mar 29, 2025 | 2.35% (0.02350) | 74.84th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.62% (0.00624) | 68.37th | v4 (v2025.03.14) |
| Dec 17, 2024 | 0.67% (0.00670) | 79.62th | v3 (v2023.03.01) |
| Jul 6, 2024 | 0.97% (0.00973) | 83.49th | v3 (v2023.03.01) |
| Feb 17, 2024 | 0.99% (0.00987) | 83.04th | v3 (v2023.03.01) |
| Feb 1, 2024 | 0.86% (0.00865) | 80.58th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.90% (0.00900) | 80.84th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.69% (0.00690) | 77.03th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.18% (0.01183) | 61.76th | v2 (v2022.01.01) |
| Oct 19, 2022 | 1.18% (0.01183) | 60.79th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.18% (0.01183) | 58.77th | v2 (v2022.01.01) |
| Feb 20, 2022 | 23.64% (0.23638) | 94.84th | v2 (v2022.01.01) |
| Feb 4, 2022 | 21.11% (0.21114) | 94.13th | v2 (v2022.01.01) |
| Feb 3, 2022 | 7.45% (0.07447) | 83.93th | v1 |
| Jan 6, 2022 | 7.45% (0.07447) | 83.77th | v1 |
| Sep 1, 2021 | 1.76% (0.01762) | 74.19th | v1 |
| Apr 14, 2021 | 1.76% (0.01762) | 0.00th | v1 |
References (19)
- https://access.redhat.com/security/cve/CVE-2020-10109 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1813447 Issue Tracking
- https://github.com/advisories/GHSA-p5xh-vx83-mxcj Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/twisted/PYSEC-2020-260.yaml
- https://github.com/twisted/twisted/blob/6ff2c40e42416c83203422ff70dfc49d2681c8e2/NEWS.rst#twisted-2030-2020-03-13
- https://github.com/twisted/twisted/blob/twisted-20.3.0/NEWS.rst
- https://github.com/twisted/twisted/commit/4a7d22e490bb8ff836892cc99a1f54b85ccb0281
- https://know.bishopfox.com/advisories x_refsource_MISCExploitThird Party Advisory
- https://know.bishopfox.com/advisories/twisted-version-19.10.0 x_refsource_MISCRelease NotesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/02/msg00021.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6ISMZFZBWW4EV6ETJGXAYIXN3AT7GBPL vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YW3NIL7VXSGJND2Q4BSXM3CFTAFU6T7D vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6ISMZFZBWW4EV6ETJGXAYIXN3AT7GBPL
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YW3NIL7VXSGJND2Q4BSXM3CFTAFU6T7D
- https://nvd.nist.gov/vuln/detail/CVE-2020-10109
- https://security.gentoo.org/glsa/202007-24 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://usn.ubuntu.com/4308-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4308-2 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-10109
Change history (0)
No recorded changes yet.