Critical severity9.8NVD Advisory· Published Mar 12, 2020· Updated Jun 17, 2026
CVE-2020-10108
CVE-2020-10108
Description
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
TwistedPyPI | < 20.3.0 | 20.3.0 |
Affected products
20- Twisted/Twisted Webdescription
- ghsa-coords8 versionspkg:pypi/twistedpkg:rpm/suse/python-Twisted&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/python-Twisted&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/python-Twisted&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/python-Twisted&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012pkg:rpm/opensuse/matrix-synapse&distro=openSUSE%20Tumbleweedpkg:rpm/suse/python-Twisted&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209pkg:rpm/suse/python-Twisted&distro=SUSE%20OpenStack%20Cloud%209
< 20.3.0+ 7 more
- (no CPE)range: < 20.3.0
- (no CPE)range: < 15.2.1-9.20.1
- (no CPE)range: < 15.2.1-9.20.1
- (no CPE)range: < 15.2.1-9.20.1
- (no CPE)range: < 15.2.1-9.20.1
- (no CPE)range: < 1.43.0-1.1
- (no CPE)range: < 15.2.1-9.20.1
- (no CPE)range: < 15.2.1-9.20.1
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:*
- cpe:2.3:o:oracle:solaris:11:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
20- www.oracle.com/security-alerts/cpuoct2020.htmlnvdPatchThird Party AdvisoryWEB
- know.bishopfox.com/advisoriesnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-h96w-mmrf-2h6vghsaADVISORY
- know.bishopfox.com/advisories/twisted-version-19.10.0nvdRelease NotesThird Party AdvisoryWEB
- lists.debian.org/debian-lts-announce/2022/02/msg00021.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-10108ghsaADVISORY
- security.gentoo.org/glsa/202007-24nvdThird Party AdvisoryWEB
- usn.ubuntu.com/4308-1/nvdThird Party Advisory
- usn.ubuntu.com/4308-2/nvdThird Party Advisory
- github.com/pypa/advisory-database/tree/main/vulns/twisted/PYSEC-2020-259.yamlghsaWEB
- github.com/twisted/twisted/blob/6ff2c40e42416c83203422ff70dfc49d2681c8e2/NEWS.rstghsaWEB
- github.com/twisted/twisted/commit/4a7d22e490bb8ff836892cc99a1f54b85ccb0281ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6ISMZFZBWW4EV6ETJGXAYIXN3AT7GBPLghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YW3NIL7VXSGJND2Q4BSXM3CFTAFU6T7DghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/6ISMZFZBWW4EV6ETJGXAYIXN3AT7GBPLghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/YW3NIL7VXSGJND2Q4BSXM3CFTAFU6T7DghsaWEB
- usn.ubuntu.com/4308-1ghsaWEB
- usn.ubuntu.com/4308-2ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6ISMZFZBWW4EV6ETJGXAYIXN3AT7GBPL/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YW3NIL7VXSGJND2Q4BSXM3CFTAFU6T7D/nvd
News mentions
0No linked articles in our index yet.