CVE-2016-5699
Summary
| CVE | CVE-2016-5699 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-09-02 14:59:07 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL. |
Risk And Classification
Primary CVSS: v3.0 6.1 MEDIUM from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS: 0.417140000 probability, percentile 0.974390000 (date 2026-05-06)
Problem Types: CWE-113 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 6.1 | MEDIUM | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| 2.0 | [email protected] | Primary | 4.3 | AV:N/AC:M/Au:N/C:N/I:P/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
ChangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Python | Python | 3.0 | All | All | All |
| Application | Python | Python | 3.0.1 | All | All | All |
| Application | Python | Python | 3.1.0 | All | All | All |
| Application | Python | Python | 3.1.1 | All | All | All |
| Application | Python | Python | 3.1.2 | All | All | All |
| Application | Python | Python | 3.1.3 | All | All | All |
| Application | Python | Python | 3.1.4 | All | All | All |
| Application | Python | Python | 3.1.5 | All | All | All |
| Application | Python | Python | 3.2.0 | All | All | All |
| Application | Python | Python | 3.2.1 | All | All | All |
| Application | Python | Python | 3.2.2 | All | All | All |
| Application | Python | Python | 3.2.3 | All | All | All |
| Application | Python | Python | 3.2.4 | All | All | All |
| Application | Python | Python | 3.2.5 | All | All | All |
| Application | Python | Python | 3.2.6 | All | All | All |
| Application | Python | Python | 3.3.0 | All | All | All |
| Application | Python | Python | 3.3.1 | All | All | All |
| Application | Python | Python | 3.3.2 | All | All | All |
| Application | Python | Python | 3.3.3 | All | All | All |
| Application | Python | Python | 3.3.4 | All | All | All |
| Application | Python | Python | 3.3.5 | All | All | All |
| Application | Python | Python | 3.3.6 | All | All | All |
| Application | Python | Python | 3.4.0 | All | All | All |
| Application | Python | Python | 3.4.1 | All | All | All |
| Application | Python | Python | 3.4.2 | All | All | All |
| Application | Python | Python | 3.4.3 | All | All | All |
| Application | Python | Python | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Splunk Enterprise 6.4.5 addresses multiple vulnerabilities | Splunk | af854a3a-2127-422b-91ae-364da2661108 | www.splunk.com | |
| Changelog — Python 3.4.5 documentation | af854a3a-2127-422b-91ae-364da2661108 | docs.python.org | Release Notes |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| cpython: bf3e1c9b80e9 | af854a3a-2127-422b-91ae-364da2661108 | hg.python.org | Patch |
| hg.python.org/cpython/raw-file/v2.7.10/Misc/NEWS | af854a3a-2127-422b-91ae-364da2661108 | hg.python.org | Release Notes |
| [security-announce] openSUSE-SU-2020:0086-1: important: Security update | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Blindspot Security | af854a3a-2127-422b-91ae-364da2661108 | blog.blindspotsecurity.com | Exploit, Third Party Advisory |
| oss-security - CVE request: Python HTTP header injection in urrlib2/urllib/httplib/http.client | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List |
| oss-security - Re: CVE request: Python HTTP header injection in urrlib2/urllib/httplib/http.client | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| cpython: 1c45047c5102 | af854a3a-2127-422b-91ae-364da2661108 | hg.python.org | Patch |
| Oracle Solaris Bulletin - July 2016 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| Python 'urrlib2/urllib/httplib/http.client' HTTP Header Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| [SECURITY] [DLA 1663-1] python3.4 security update | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | |
| oss-security - Re: CVE request: Python HTTP header injection in urrlib2/urllib/httplib/http.client | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Splunk Enterprise 6.5.1 addresses multiple OpenSSL vulnerabilities | Splunk | af854a3a-2127-422b-91ae-364da2661108 | www.splunk.com | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| CVE-2016-5699 - Red Hat Customer Portal | MITRE | access.redhat.com | |
| 1303699 – (CVE-2016-5699) CVE-2016-5699 python: http protocol steam injection attack | MITRE | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 730315 Splunk Enterprise and Light Security Update (SP-CAAAPSV) (SPL-128812)