An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
https://www.kb.cert.org/vuls/id/127587
https://pointernull.com/security/python-url-parse-problem.html
https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html
https://lists.debian.org/debian-lts-announce/2024/11/msg00005.html
https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html