Lucene search

K
osvGoogleOSV:PYSEC-2020-148
HistorySep 30, 2020 - 6:15 p.m.

PYSEC-2020-148

2020-09-3018:15:00
Google
osv.dev
72

0.004 Low

EPSS

Percentile

74.7%

urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.