Safety vulnerability ID: 37055
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Urllib3 1.24.3 includes a fix for CVE-2019-11236: CRLF injection is possible if the attacker controls the request parameter.
https://github.com/urllib3/urllib3/commit/5d523706c7b03f947dc50a7e783758a2bfff0532
https://github.com/urllib3/urllib3/issues/1553
Latest version: 2.2.3
HTTP library with thread-safe connection pooling, file post, and more.
In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.
MISC:https://github.com/urllib3/urllib3/issues/1553: https://github.com/urllib3/urllib3/issues/1553
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application