Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-0391

29
FAUCET Score

CVE-2022-0391 is a high-severity vulnerability (CVSS 7.5) in Python's urllib.parse module, affecting versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11, and 3.6.14, as well as products like Fedora, NetApp, and Oracle. The flaw allows an attacker to inject crafted URLs containing unsanitized characters like carriage returns and newlines, leading to injection attacks. This vulnerability has a low attack complexity and does not require user interaction, posing a significant integrity risk. There is currently no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.6.14CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.7.0, < 3.7.11CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.8.0, < 3.8.11CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.9.0, < 3.9.5CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
3.10.0CPE matchmatch criteria
cpe:2.3:a:python:python:3.10.0:alpha1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
8.62%
Probability of exploitation in next 30 days
EPSS Percentile
94.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0862 is in the 91st percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (30)

microsoftpatch availablevia msrc
Product: 18794-16820Fixed in: 3.7.10-6
microsoftpatch availablevia msrc
Product: 18795-16820Fixed in: 2.7.18-9
microsoftpatch availablevia msrc
Product: cm1 python2 2.7.18-9 on CBL Mariner 1.0Fixed in: 2.7.18-9
microsoftpatch availablevia msrc
Product: cm1 python3 3.7.10-6 on CBL Mariner 1.0Fixed in: 3.7.10-6
nodejspatch availablevia llm_extracted
View patch
nodejspatch availablevia llm_extracted
Fixed in: 25.4.0
oraclepatch availablevia nvd_reference
View patch
pjsippatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-python38-python-0:3.8.11-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-python38-python-cryptography-0:2.8-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-python38-python-jinja2-0:2.10.3-6.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-python38-python-lxml-0:4.4.1-7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-python38-python-pip-0:19.3.1-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-python38-python-urllib3-0:1.25.7-7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: python27-python-0:2.7.18-4.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-python38-babel-0:2.7.0-12.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-python38-python-0:3.8.11-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-python38-python-cryptography-0:2.8-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-python38-python-jinja2-0:2.10.3-6.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-python38-python-lxml-0:4.4.1-7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-python38-python-pip-0:19.3.1-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-python38-python-urllib3-0:1.25.7-7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python38:3.8-8060020220120164031.5294be16
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python27:2.7-8060020220210185952.8cdc2268
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python38-devel:3.8-8060020220120164031.5294be16
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-python38-babel-0:2.7.0-12.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3-0:3.6.8-47.el8_6
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: inkscape:flatpak/python2
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python39:3.9/python39
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gimp:flatpak/python2

Vendor Advisories (5)

nodejsllm-nodejs-9e1762a1939f642dCRITICAL

Third-Party Package Updates in Splunk AppDynamics On-Premises Enterprise Console - August 2025

Aug 6, 2025
nodejsllm-nodejs-302528ae26f0d946CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
pjsipllm-pjsip-7ba3ec379210ac70CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
microsoft2022-Feb/CVE-2022-0391Important

A flaw was found in Python specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1 3.9.5 3.8.11 3.7.11 and 3.6.14.

Feb 8, 2022
redhatCVE-2022-0391Moderate

python: urllib.parse does not sanitize URLs containing ASCII newline and tabs

Apr 18, 2021

References

lists.debian.org / debian-lts-announce/2024/11/msg00024.html
lists.debian.org / debian-lts-announce/2025/03/msg00013.html
bugs.python.org / issue43882
ExploitIssue TrackingPatchVendor Advisory
lists.debian.org / debian-lts-announce/2023/09/msg00022.html
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/CSD2YBXP3ZF44E44QMIIAR5VTO35KTRB
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/UDBDBAU6HUPZHISBOARTXZ5GKHF2VH5U
security.gentoo.org / glsa/202305-02
security.netapp.com / advisory/ntap-20220225-0009
Third Party Advisory
oracle.com / security-alerts/cpuapr2022.html
PatchThird Party Advisory