First published: Mon Nov 16 2020(Updated: )
In JetBrains Ktor before 1.4.1, HTTP request smuggling was possible.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains Ktor | <1.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-26129 is medium with a severity value of 6.5.
JetBrains Ktor versions up to and excluding 1.4.1 are affected by CVE-2020-26129.
CVE-2020-26129 is about the possibility of HTTP request smuggling in JetBrains Ktor versions before 1.4.1.
To fix CVE-2020-26129, upgrade JetBrains Ktor to version 1.4.1 or higher.
More information about CVE-2020-26129 can be found in the JetBrains Security Bulletin Q3 2020: https://blog.jetbrains.com/2020/11/16/jetbrains-security-bulletin-q3-2020/