Pypiserver through 1.2.5 and below is susceptible to carriage return line feed injection. An attacker can set arbitrary HTTP headers and possibly conduct cross-site scripting attacks via a %0d%0a in a URI.
id: CVE-2019-6802
info:
name: Pypiserver <1.2.5 - Carriage Return Line Feed Injection
author: 0
...