Junglewise Threat Intelligence

CVE-2019-11236: PYSEC-2019-132 - In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.

CVE-2019-11236 · Severity: low · CVSS 3 · Published 2019-04-15

Technologies: urllib3 (PyPI). Vendors: PyPI.

Executive brief

In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.

Affected products

  • PyPI urllib3

Related threats