CVE-2019-6802: Python Pypiserver

Medium severity, CVSS 6.1. EPSS: 3.8% chance of exploitation in the next 30 days.

CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI.

Affected products

  • Python Pypiserver: up to and including 1.2.5

Published 2019-01-25. Last modified 2026-06-17.