Critical severity9.8NVD Advisory· Published Jan 30, 2021· Updated Jun 17, 2026
CVE-2020-15690
CVE-2020-15690
Description
In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline character.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- Nim/Nimdescription
- osv-coords5 versionspkg:rpm/suse/nim&distro=SUSE%20Package%20Hub%2015%20SP3pkg:rpm/opensuse/nim&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/nim&distro=SUSE%20Package%20Hub%2015%20SP4pkg:rpm/opensuse/nim&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/nim&distro=openSUSE%20Tumbleweed
< 1.6.6-bp153.2.3.1+ 4 more
- (no CPE)range: < 1.6.6-bp153.2.3.1
- (no CPE)range: < 1.6.6-bp153.2.3.1
- (no CPE)range: < 1.6.6-bp154.2.3.1
- (no CPE)range: < 1.6.6-bp154.2.3.1
- (no CPE)range: < 1.6.6-3.1
Patches
Vulnerability mechanics
References
5- github.com/nim-lang/Nim/compare/v1.2.4...v1.2.6nvdPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2021/02/04/3nvdExploitMailing ListThird Party Advisory
- consensys.net/diligence/vulnerabilities/nim-asyncftpd-crlf-injection/nvdExploitThird Party Advisory
- github.com/nim-lang/Nim/blob/dc5a40f3f39c6ea672e6dc6aca7f8118a69dda99/lib/pure/asyncftpclient.nimnvdExploitThird Party Advisory
- github.com/tintinweb/pub/tree/master/pocs/cve-2020-15690nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.