USN-4570-1: urllib3 vulnerability
Published Oct 5, 2020
·Updated
It was discovered that urllib3 incorrectly handled certain character sequences. A remote attacker could possibly use this issue to perform CRLF injection.
Affected Software
1 affected component
pypi/urllib3
Event History
Feb 23, 2026
Advisory Published
via Ubuntu·09:43 PM
Data Sourced
via Ubuntu·09:43 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of USN-4570-1?
The severity of USN-4570-1 is moderate.
2
How does the urllib3 vulnerability impact my system?
The urllib3 vulnerability could allow a remote attacker to perform CRLF injection.
3
Which versions of Ubuntu are affected by USN-4570-1?
Ubuntu 16.04, 18.04, and 20.04 are affected by USN-4570-1.
4
How do I fix the urllib3 vulnerability on Ubuntu 20.04?
To fix the urllib3 vulnerability on Ubuntu 20.04, upgrade the python3-urllib3 package to version 1.25.8-2ubuntu0.1 or higher.
5
Where can I find more information about the urllib3 vulnerability?
You can find more information about the urllib3 vulnerability on the Ubuntu Security Advisory USN-4570-1 page.