CVE-2019-11236
published 2019-04-15CVE-2019-11236: In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.
PriorityP430medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
2.06%
79.1th percentile
In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | python-urllib3 | < python-urllib3 1.25.6-4 (bookworm) | python-urllib3 1.25.6-4 (bookworm) |
| msrc | cbl2_python-virtualenv_20.26.6-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_python-urllib3_1.25.9-2_on_cbl_mariner_1.0 | — | — |
| python | urllib3 | <= 1.24.2 | — |
| urllib3 | urllib3 | >= 0 < 1.24.3 | 1.24.3 |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian6.1MEDIUM
vendor_msrc6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Neutralization of CRLF Sequences in urllib3 library for Python
ghsa·2022-05-13
CVE-2019-11236 [MEDIUM] CWE-93 Improper Neutralization of CRLF Sequences in urllib3 library for Python
Improper Neutralization of CRLF Sequences in urllib3 library for Python
In the urllib3 library through 1.24.2 for Python, CRLF injection is possible if the attacker controls the request parameter.
OSV
Improper Neutralization of CRLF Sequences in urllib3 library for Python
osv·2022-05-13
CVE-2019-11236 [MEDIUM] Improper Neutralization of CRLF Sequences in urllib3 library for Python
Improper Neutralization of CRLF Sequences in urllib3 library for Python
In the urllib3 library through 1.24.2 for Python, CRLF injection is possible if the attacker controls the request parameter.
OSV
python-urllib3 vulnerability
osv·2019-07-29·CVSS 6.1
CVE-2019-11236 [MEDIUM] python-urllib3 vulnerability
python-urllib3 vulnerability
USN-3990-1 fixed a vulnerability in urllib3. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that urllib3 incorrectly stripped certain characters from
requests. A remote attacker could use this issue to perform CRLF injection.
(CVE-2019-11236)
OSV
python-urllib3 vulnerabilities
osv·2019-05-21·CVSS 9.8
CVE-2018-20060 [CRITICAL] python-urllib3 vulnerabilities
python-urllib3 vulnerabilities
It was discovered that urllib3 incorrectly removed Authorization HTTP
headers when handled cross-origin redirects. This could result in
credentials being sent to unintended hosts. This issue only affected Ubuntu
16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-20060)
It was discovered that urllib3 incorrectly stripped certain characters from
requests. A remote attacker could use this issue to perform CRLF injection.
(CVE-2019-11236)
It was discovered that urllib3 incorrectly handled situations where a
desired set of CA certificates were specified. This could result in
certificates being accepted by the default CA certificates contrary to
expectations. This issue only affected Ubuntu 18.04 LTS, Ubuntu 18.10, and
Ubuntu 19.04. (CVE-2019-11324)
OSV
CVE-2019-11236: In the urllib3 library through 1
osv·2019-04-15·CVSS 6.1
CVE-2019-11236 [MEDIUM] CVE-2019-11236: In the urllib3 library through 1
In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.
Ubuntu
urllib3 vulnerability
vendor_ubuntu·2019-07-29·CVSS 6.1
CVE-2019-11236 [MEDIUM] urllib3 vulnerability
Title: urllib3 vulnerability
Summary: urllib3 could be used to perform a CRLF injection if it received a specially
crafted request.
USN-3990-1 fixed a vulnerability in urllib3. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that urllib3 incorrectly stripped certain characters from
requests. A remote attacker could use this issue to perform CRLF injection.
(CVE-2019-11236)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
urllib3 vulnerabilities
vendor_ubuntu·2019-05-21·CVSS 9.8
CVE-2018-20060 [CRITICAL] urllib3 vulnerabilities
Title: urllib3 vulnerabilities
Summary: Several security issues were fixed in urllib3.
It was discovered that urllib3 incorrectly removed Authorization HTTP
headers when handled cross-origin redirects. This could result in
credentials being sent to unintended hosts. This issue only affected Ubuntu
16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-20060)
It was discovered that urllib3 incorrectly stripped certain characters from
requests. A remote attacker could use this issue to perform CRLF injection.
(CVE-2019-11236)
It was discovered that urllib3 incorrectly handled situations where a
desired set of CA certificates were specified. This could result in
certificates being accepted by the default CA certificates contrary to
expectations. This issue only affected Ubuntu 18.04 LTS,
Microsoft
In the urllib3 library through 1.24.1 for Python CRLF injection is possible if the attacker controls the request parameter.
vendor_msrc·2019-04-09·CVSS 6.1
CVE-2019-11236 [MEDIUM] CWE-93 In the urllib3 library through 1.24.1 for Python CRLF injection is possible if the attacker controls the request parameter.
In the urllib3 library through 1.24.1 for Python CRLF injection is possible if the attacker controls the request parameter.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Requir
Red Hat
python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service
vendor_redhat·2019-03-13·CVSS 6.1
CVE-2019-11236 [MEDIUM] CWE-113 python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service
python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service
In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.
Statement: This issue affects the version of python-urllib3 shipped with Red Hat Gluster Storage 3, as it is vulnerable to CRLF injection.
Red Hat Satellite 6.2 is on Maintenance Support 2 phase, hence only selected critical and important issues will be fixed. Please refer to Red Hat Satellite Product Life Cycle page for more information.
In Red Hat OpenStack Platform 13, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP python-urllib3 package.
Pa
Debian
CVE-2019-11236: python-urllib3 - In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if ...
vendor_debian·2019·CVSS 6.1
CVE-2019-11236 [MEDIUM] CVE-2019-11236: python-urllib3 - In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if ...
In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.
Scope: local
bookworm: resolved (fixed in 1.25.6-4)
bullseye: resolved (fixed in 1.25.6-4)
forky: resolved (fixed in 1.25.6-4)
sid: resolved (fixed in 1.25.6-4)
trixie: resolved (fixed in 1.25.6-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-11236 python3-virtualenv: python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service [epel-7]
bugzilla·2019-11-29·CVSS 6.1
CVE-2019-11236 [MEDIUM] CVE-2019-11236 python3-virtualenv: python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service [epel-7]
CVE-2019-11236 python3-virtualenv: python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and
Bugzilla
CVE-2019-11236 python-virtualenv: python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service [epel-6]
bugzilla·2019-11-29·CVSS 6.1
CVE-2019-11236 [MEDIUM] CVE-2019-11236 python-virtualenv: python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service [epel-6]
CVE-2019-11236 python-virtualenv: python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and t
Bugzilla
CVE-2019-11236 python-virtualenv: python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service [fedora-30]
bugzilla·2019-11-29·CVSS 6.1
CVE-2019-11236 [MEDIUM] CVE-2019-11236 python-virtualenv: python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service [fedora-30]
CVE-2019-11236 python-virtualenv: python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service [fedora-30]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-30.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog
Bugzilla
CVE-2019-11236 python-pip: python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service [epel-6]
bugzilla·2019-11-21·CVSS 6.1
CVE-2019-11236 [MEDIUM] CVE-2019-11236 python-pip: python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service [epel-6]
CVE-2019-11236 python-pip: python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedp
Bugzilla
CVE-2019-11236 python-pip-epel: python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service [epel-7]
bugzilla·2019-11-21·CVSS 6.1
CVE-2019-11236 [MEDIUM] CVE-2019-11236 python-pip-epel: python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service [epel-7]
CVE-2019-11236 python-pip-epel: python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bugzilla
CVE-2019-11236 python-pip: python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service [fedora-all]
bugzilla·2019-11-21·CVSS 6.1
CVE-2019-11236 [MEDIUM] CVE-2019-11236 python-pip: python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service [fedora-all]
CVE-2019-11236 python-pip: python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and
Bugzilla
CVE-2019-11236 python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service [openstack-rdo]
bugzilla·2019-05-06·CVSS 6.1
CVE-2019-11236 [MEDIUM] CVE-2019-11236 python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service [openstack-rdo]
CVE-2019-11236 python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fe
Bugzilla
CVE-2019-11236 python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service. [fedora-all]
bugzilla·2019-04-17·CVSS 6.1
CVE-2019-11236 [MEDIUM] CVE-2019-11236 python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service. [fedora-all]
CVE-2019-11236 python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service. [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg
Bugzilla
CVE-2019-11236 python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service
bugzilla·2019-04-17·CVSS 6.1
CVE-2019-11236 [MEDIUM] CVE-2019-11236 python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service
CVE-2019-11236 python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service
The current implementation of python-urllib3 does not encode the ‘\r\n’ sequence in the query string, which allowed the attacker to manipulate a HTTP header with the ‘\r\n’ sequence in it, so the attacker could insert arbitrary content to the new line of the HTTP header.
External References:
https://bugs.python.org/issue36276
Discussion:
Created python-urllib3 tracking bugs for this issue:
Affects: fedora-all [bug 1700825]
---
Additional references:
https://github.com/urllib3/urllib3/issues/1553
https://github.com/urllib3/urllib3/commit/0aa3e24fcd75f1bb59ab159e9f8adb44055b2271
---
This issue is reproducible on Red Hat Gluster Storage 3, successfully
Bugzilla
CVE-2019-9947 python: CRLF injection via the path part of the url passed to urlopen()
bugzilla·2019-04-03·CVSS 6.1
CVE-2019-9947 [MEDIUM] CVE-2019-9947 python: CRLF injection via the path part of the url passed to urlopen()
CVE-2019-9947 python: CRLF injection via the path part of the url passed to urlopen()
An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in
Python 3.x through 3.7.2. CRLF injection is possible if the attacker controls a
url parameter, as demonstrated by the first argument to urllib.request.urlopen
with \r\n (specifically in the path component of a URL) followed by an HTTP
header or a Redis command. This is similar to CVE-2019-9740 query string issue.
Reference:
https://bugs.python.org/issue35906
Discussion:
Created python-urllib3 tracking bugs for this issue:
Affects: fedora-all [bug 1695599]
---
Created python3-urllib3 tracking bugs for this issue:
Affects: epel-all [bug 1695600]
---
The main Python issue became https://bugs.python.org/issue30458 which is
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00039.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00041.htmlhttps://access.redhat.com/errata/RHSA-2019:2272https://access.redhat.com/errata/RHSA-2019:3335https://access.redhat.com/errata/RHSA-2019:3590https://github.com/urllib3/urllib3/issues/1553https://lists.debian.org/debian-lts-announce/2019/06/msg00016.htmlhttps://lists.debian.org/debian-lts-announce/2021/06/msg00015.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00012.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NKGPJLVLVYCL4L4B4G5TIOTVK4BKPG72/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R62XGEYPUTXMRHGX5I37EBCGQ5COHGKR/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TBI45HO533KYHNB5YRO43TBYKA3E3VRL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOSA2NT4DUQDBEIWE6O7KKD24XND7TE2/https://usn.ubuntu.com/3990-1/https://usn.ubuntu.com/3990-2/http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00039.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00041.htmlhttps://access.redhat.com/errata/RHSA-2019:2272https://access.redhat.com/errata/RHSA-2019:3335https://access.redhat.com/errata/RHSA-2019:3590https://github.com/urllib3/urllib3/issues/1553https://lists.debian.org/debian-lts-announce/2019/06/msg00016.htmlhttps://lists.debian.org/debian-lts-announce/2021/06/msg00015.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00012.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NKGPJLVLVYCL4L4B4G5TIOTVK4BKPG72/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R62XGEYPUTXMRHGX5I37EBCGQ5COHGKR/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TBI45HO533KYHNB5YRO43TBYKA3E3VRL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOSA2NT4DUQDBEIWE6O7KKD24XND7TE2/https://usn.ubuntu.com/3990-1/https://usn.ubuntu.com/3990-2/
2019-04-15
Published