CVE-2019-11236

MEDIUM

urllib3 <1.24.1 - CRLF Injection

Title source: llm
STIX 2.1

Description

In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.

References (15)

Scores

CVSS v3 6.1
EPSS 0.0057
EPSS Percentile 68.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-93
Status published
Products (2)
pypi/urllib3 0 - 1.24.3PyPI
python/urllib3 < 1.24.2
Published Apr 15, 2019
Tracked Since Feb 18, 2026