Medium severity5.3NVD Advisory· Published Mar 11, 2020· Updated Jun 17, 2026
CVE-2016-1000111
CVE-2016-1000111
Description
Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
TwistedPyPI | < 16.3.1 | 16.3.1 |
Affected products
7- Twisted/Twisteddescription
- ghsa-coords5 versionspkg:pypi/twistedpkg:rpm/opensuse/python-Twisted&distro=openSUSE%20Tumbleweedpkg:rpm/suse/python-Twisted&distro=SUSE%20Enterprise%20Storage%203pkg:rpm/suse/python-Twisted&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/python-Twisted&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012
< 16.3.1+ 4 more
- (no CPE)range: < 16.3.1
- (no CPE)range: < 16.4.1-1.2
- (no CPE)range: < 15.2.1-8.1
- (no CPE)range: < 15.2.1-8.1
- (no CPE)range: < 15.2.1-8.1
Patches
Vulnerability mechanics
References
7- twistedmatrix.com/trac/ticket/8623nvdPatchVendor AdvisoryWEB
- www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.htmlnvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-3gqj-cmxr-p4x2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2016-1000111ghsaADVISORY
- twistedmatrix.com/pipermail/twisted-web/2016-August/005268.htmlnvdMailing ListVendor AdvisoryWEB
- www.openwall.com/lists/oss-security/2016/07/18/6nvdMailing ListThird Party AdvisoryWEB
- github.com/pypa/advisory-database/tree/main/vulns/twisted/PYSEC-2020-214.yamlghsaWEB
News mentions
0No linked articles in our index yet.