It was discovered that urllib3 incorrectly stripped certain characters from requests. A remote attacker could use this issue to perform CRLF injection (CVE-2019-11236).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2019-0259.json"