Junglewise Threat Intelligence

CVE-2020-10109: PYSEC-2020-260 - In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encodi

CVE-2020-10109 · Severity: low · CVSS 3.1 · Published 2020-03-12

Technologies: twisted (PyPI). Vendors: PyPI.

Executive brief

In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request body was interpreted as a pipelined request.

Affected products

  • PyPI twisted

Related threats