CVE-2019-6802: Python Pypiserver
Medium severity, CVSS 6.1. EPSS: 3.8% chance of exploitation in the next 30 days.
CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI.
Affected products
- Python Pypiserver: up to and including 1.2.5
Published 2019-01-25. Last modified 2026-06-17.