CVE-2020-26129: Medium severity ktor vulnerability
Published Nov 16, 2020
·Updated
In JetBrains Ktor before 1.4.1, HTTP request smuggling was possible.
Affected Software
1 affected component
JetBrains Ktor<1.4.1
Event History
Nov 16, 2020
CVE Published
via MITRE·03:09 PM
Data Sourced
via MITRE·03:09 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-26129?
The severity of CVE-2020-26129 is medium with a severity value of 6.5.
2
What software is affected by CVE-2020-26129?
JetBrains Ktor versions up to and excluding 1.4.1 are affected by CVE-2020-26129.
3
What is CVE-2020-26129 about?
CVE-2020-26129 is about the possibility of HTTP request smuggling in JetBrains Ktor versions before 1.4.1.
4
How can I fix CVE-2020-26129?
To fix CVE-2020-26129, upgrade JetBrains Ktor to version 1.4.1 or higher.
5
Where can I find more information about CVE-2020-26129?
More information about CVE-2020-26129 can be found in the JetBrains Security Bulletin Q3 2020: https://blog.jetbrains.com/2020/11/16/jetbrains-security-bulletin-q3-2020/