In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.
{
"nvd_published_at": "2019-06-10T12:29:00Z",
"github_reviewed": true,
"github_reviewed_at": "2019-06-10T18:04:12Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-74",
"CWE-93"
]
}