Description
In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.
References (15)
Scores
CVSS v3
6.1
EPSS
0.0057
EPSS Percentile
68.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-93
Status
published
Products (2)
pypi/urllib3
0 - 1.24.3PyPI
python/urllib3
< 1.24.2
Published
Apr 15, 2019
Tracked Since
Feb 18, 2026