S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Feb 1, 2024

CVE-2019-6802 Scanner

CVE-2019-6802 scanner - Carriage Return Line Feed Injection vulnerability in Pypiserver

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-6802
6.1
CVSS

CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Pypiserver is a popular open source tool used for hosting and serving Python packages. This lightweight package application is used in organizations to simplify the process of distributing, installing, and managing Python packages. By using Pypiserver, developers can manage and distribute Python packages without relying on external package repositories. This makes the deployment and management of Python packages easier, faster, and more secure.

The CVE-2019-6802 vulnerability is a critical security flaw that was detected in Pypiserver version 1.2.5 and below. The flaw, also known as CRLF Injection, enables hackers to set arbitrary HTTP headers and potentially launch Cross-Site Scripting attacks by inserting a %0d%0a in a URI. Hackers can manipulate this technique to inject malicious scripts that could ultimately lead to a full-scale attack on the system.

When this vulnerability is exploited, it can cause serious harm to the entire Python package ecosystem. The consequences of exploiting the vulnerability include sensitive data leaks, cross-site scripting attacks, compromise of Python environments, and unauthorized access to internal systems. The potential damage of such an attack on an organization can be catastrophic, both financially and in terms of business continuity.

Thanks to the pro features of the s4e.io platform, individuals and organizations can easily and quickly learn about vulnerabilities in their digital assets. With a wealth of expertly-curated security information, tools, and resources, the platform offers a comprehensive solution for keeping digital assets safe and secure. By taking advantage of the platform's features, users can protect their systems from the impact of CVE-2019-6802 and other security risks.

 

REFERENCES

Solution Advice

To mitigate the risk of this vulnerability, users of Pypiserver can take certain precautions. Some of the most effective measures to protect against the CVE-2019-6802 vulnerability include:

  • Upgrading to the latest version of Pypiserver that provides a fix for the flaw.
  • Implementing security controls on the web server to block malicious input.
  • Deploying an intrusion detection system to detect and prevent CRLF injection attacks.
  • Educating developers and security teams on best practices for Python package management.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-6802 scanner - Carriage Return Line Feed Injection vulnerability in Pypiserver S4E