{"id":"UBUNTU-CVE-2020-35678","details":"Autobahn|Python before 20.12.3 allows redirect header injection.","modified":"2026-05-20T16:06:23.786593300Z","published":"2020-12-27T00:15:00Z","upstream":["CVE-2020-35678"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2020-35678"},{"type":"REPORT","url":"https://github.com/crossbario/autobahn-python/pull/1439"},{"type":"REPORT","url":"https://github.com/crossbario/autobahn-python/commit/f7b7ad5c1066bdcc551775b73da15dca5c111623"},{"type":"REPORT","url":"https://autobahn.readthedocs.io/en/latest/changelog.html"},{"type":"REPORT","url":"https://github.com/crossbario/autobahn-python"},{"type":"REPORT","url":"https://github.com/crossbario/autobahn-python/compare/v20.12.2...v20.12.3"},{"type":"REPORT","url":"https://pypi.org/project/autobahn/20.12.3/"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2020-35678"}],"affected":[{"package":{"name":"python-autobahn","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/python-autobahn?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.10.3+dfsg1-2","0.10.3+dfsg1-3","0.10.3+dfsg1-5"],"ecosystem_specific":{"binaries":[{"binary_name":"python-autobahn","binary_version":"0.10.3+dfsg1-5"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-35678.json"}},{"package":{"name":"python-autobahn","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/python-autobahn?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.14.1+dfsg1-2ubuntu1","17.10.1+dfsg1-2"],"ecosystem_specific":{"binaries":[{"binary_name":"python-autobahn","binary_version":"17.10.1+dfsg1-2"},{"binary_version":"17.10.1+dfsg1-2","binary_name":"python3-autobahn"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-35678.json"}},{"package":{"name":"python-autobahn","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/python-autobahn?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["17.10.1+dfsg1-5","17.10.1+dfsg1-6"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-autobahn","binary_version":"17.10.1+dfsg1-6"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-35678.json"}},{"package":{"name":"python-autobahn","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/python-autobahn?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["17.10.1+dfsg1-7","21.11.1+dfsg1-2","21.11.1+dfsg1-2build1"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-autobahn","binary_version":"21.11.1+dfsg1-2build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-35678.json"}},{"package":{"name":"python-autobahn","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/python-autobahn?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["22.7.1+dfsg1-3","22.7.1+dfsg1-4"],"ecosystem_specific":{"binaries":[{"binary_version":"22.7.1+dfsg1-4","binary_name":"python3-autobahn"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-35678.json"}},{"package":{"name":"python-autobahn","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/python-autobahn?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["23.1.2+dfsg1-2"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-autobahn","binary_version":"23.1.2+dfsg1-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-35678.json"}},{"package":{"name":"python-autobahn","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/python-autobahn?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["23.1.2+dfsg1-2","24.4.2+dfsg1-4","24.4.2+dfsg1-5"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-autobahn","binary_version":"24.4.2+dfsg1-5"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-35678.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"Ubuntu","score":"medium"}]}