VYPR
Medium severity6.1OSV Advisory· Published Jan 25, 2019· Updated Jun 17, 2026

CVE-2019-6802

CVE-2019-6802

Description

CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
pypiserverPyPI
< 1.2.61.2.6

Affected products

3

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.