Safety vulnerability ID: 37209
The information on this page was manually curated by our Cybersecurity Intelligence Team.
In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.
Latest version: 24.11.0
An asynchronous networking framework written in Python
In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.
CONFIRM:https://github.com/twisted/twisted/commit/6c61fc4503ae39ab8ecee52d10f10ee2c371d7e2: https://github.com/twisted/twisted/commit/6c61fc4503ae39ab8ecee52d10f10ee2c371d7e2
CONFIRM:https://labs.twistedmatrix.com/2019/06/twisted-1921-released.html: https://labs.twistedmatrix.com/2019/06/twisted-1921-released.html
CONFIRM:https://twistedmatrix.com/pipermail/twisted-python/2019-June/032352.html: https://twistedmatrix.com/pipermail/twisted-python/2019-June/032352.html
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application