CVE-2019-12387: Canonical Ubuntu Linux

Medium severity, CVSS 6.1. EPSS: 2.5% chance of exploitation in the next 30 days.

In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 19.10 only
  • Fedoraproject Fedora: version 29 only
  • Oracle Solaris: version 11 only
  • Oracle ZFS Storage Appliance Kit: version 8.8 only
  • Twisted Twisted: before 19.2.1 (fixed in 19.2.1)

Published 2019-06-10. Last modified 2026-06-17.