invenio-app before 1.1.1 allows host header injection.
"https://github.com/pypa/advisory-database/blob/main/vulns/invenio-app/PYSEC-2019-24.yaml"