CVE-2019-11236

MEDIUM

urllib3 <1.24.1 - CRLF Injection

Title source: llm

Description

In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.

References (15)

Scores

CVSS v3 6.1
EPSS 0.0062
EPSS Percentile 69.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Classification

CWE
CWE-93
Status published

Affected Products (2)

python/urllib3 < 1.24.2
pypi/urllib3 < 1.24.3PyPI

Timeline

Published Apr 15, 2019
Tracked Since Feb 18, 2026