GHSA-gg84-qgv9-w4pq · Severity: medium · Ecosystem: pip — CRLF injection in httplib2
In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden requests to same server. This vulnerability impacts software that uses httplib2 with uri constructed by string concatenation, as opposed to proper urllib building with escaping. This has been fixed in 0.18.0.
Conclusion & alert: CVE-2020-11078 is rated Moderate Risk (57.7/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 3.28%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-01-28 | 3.19% | 3.28% | +0.08% |
| 2 | 2025-11-21 | 3.13% | 3.19% | +0.07% |
| 3 | 2025-11-18 | — | 3.13% | — |
Full EPSS history (14 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.8 | 3.1 | MEDIUM |
|
2.2 | 4.0 | [email protected] |
| 6.8 | 3.1 | MEDIUM |
|
2.2 | 4.0 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
GHSA-gg84-qgv9-w4pq · Severity: medium · Ecosystem: pip — CRLF injection in httplib2
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2020-11078 not yet assigned priority: Debian including 1 source packages (python-httplib2), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2020-11078 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2020-11078 |
suse
|
medium | CVE-2020-11078 severity moderate: SUSE including 301 source package names (0.1.75:python3-httplib2-0.19.0-3.3.1, 1.1.1.0.1.5.424:python3-httplib2-0.19.0-3.3.1, …), 338 product×package rows across 57 product lines (Container caasp/v4/k8s-sidecar, Container ses/6/cephcsi/cephcsi, … (57 product lines)): Known Affected 231, Fixed 107. | https://www.suse.com/security/cve/CVE-2020-11078/ |
ubuntu
|
low | CVE-2020-11078 low priority: Ubuntu including 1 source packages (python-httplib2), 17 status rows across 17 suites (bionic, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): not-affected 11, needed 4, ignored 1, released 1. | https://ubuntu.com/security/CVE-2020-11078 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| httplib2_project | httplib2 | < 0.18.0 | cpe:2.3:a:httplib2_project:httplib2:*:*:*:*:*:*:*:* |
| fedoraproject | fedora | 31 | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* |
| fedoraproject | fedora | 32 | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* |
| debian | debian_linux | 8.0 | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |