VDB
KO

PYSEC-2019-132

Details

In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / urllib3
Introduced in: 0 Fixed in: 1.24.3
Fix pip install --upgrade 'urllib3>=1.24.3'

References