CVE advisoryCRITICAL
CVE-2019-9948
Python Urllib local file bypass vulnerability.
Halo Surface Signal: 3 out of 5 — possibly public-facing.
A vulnerability in Python's urllib library allows remote attackers to bypass file access controls by using a local file scheme in URLs. This could enable unauthorized access to sensitive local files if applications process external URLs without proper validation. Readers should assess the relevance and exposure of this