Lucene search

K
osvGoogleOSV:CVE-2020-7695
HistoryJul 27, 2020 - 12:15 p.m.

CVE-2020-7695

2020-07-2712:15:11
Google
osv.dev
9
uvicorn
http response splitting
crlf sequences
http headers
attackers
crafted input

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

38.8%

Uvicorn before 0.11.7 is vulnerable to HTTP response splitting. CRLF sequences are not escaped in the value of HTTP headers. Attackers can exploit this to add arbitrary headers to HTTP responses, or even return an arbitrary response body, whenever crafted input is used to construct HTTP headers.

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

38.8%