Vulnerability DatabaseCVE-2016-1000111

CVE-2016-1000111
Python vulnerability analysis and mitigation

Overview

CVE-2016-1000111 affects Twisted versions before 16.3.1. The vulnerability relates to the handling of HTTP_PROXY environment variable in CGI scripts. The issue was discovered by Scott Geary from VendHQ and was fixed in Twisted 16.3.1 released in August 2016 (Red Hat Advisory, Debian Tracker).

Technical details

The vulnerability occurs because Twisted does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable. The vulnerability has a CVSS v3.1 base score of 5.3 (MEDIUM) with vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N (NVD).

Impact

A remote attacker could potentially use this vulnerability to redirect HTTP requests performed by a CGI script to an attacker-controlled proxy via a malicious HTTP request. This allows the attacker to intercept and potentially modify outbound HTTP traffic from the affected CGI application (Red Hat Advisory).

Mitigation and workarounds

The vulnerability was fixed in Twisted version 16.3.1. After applying the fix, python-twisted-web no longer passes the value of the Proxy request header to scripts via the HTTP_PROXY environment variable. Users are advised to upgrade to version 16.3.1 or later (Twisted Announcement).

Community reactions

The vulnerability was part of a broader class of CGI application vulnerabilities affecting multiple languages and frameworks including PHP, Go, Python and others. It was tracked as part of the 'httpoxy' vulnerability set which resulted in multiple CVEs being assigned to different affected software (OSS Security).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22033HIGH8.6
  • PythonPython
  • label-studio
NoNoJan 12, 2026
CVE-2025-68472HIGH8.1
  • PythonPython
  • mindsdb
NoYesJan 12, 2026
CVE-2026-22251MEDIUM5.3
  • PythonPython
  • wlc
NoYesJan 12, 2026
CVE-2026-22691LOW2.7
  • PythonPython
  • pypdf
NoYesJan 10, 2026
CVE-2026-22250LOW2.5
  • PythonPython
  • wlc
NoYesJan 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management