{"id":"CVE-2018-20852","title":"http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into sending existing cookies to the wrong server","summary":"http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into sending existing cookies to the wrong server. An attacker may abuse this flaw by…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","cwe":["CWE-20"],"vendor":"python","product":"python","affected":["python >= 2.0, <= 2.7.16","python >= 3.0.0, < 3.4.10","python >= 3.5.0, < 3.5.7","python >= 3.6.0, < 3.6.9","python >= 3.7.0, < 3.7.3"],"patched":["python 3.7.3"],"published":"2019-07-13","updated":"2026-10-07","sourceUpdated":"2026-10-07T19:17:11.553","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2018-20852","references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00071.html","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00074.html","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","label":"cve@mitre.org"},{"url":"https://access.redhat.com/errata/RHSA-2019:3725","label":"cve@mitre.org"},{"url":"https://access.redhat.com/errata/RHSA-2019:3948","label":"cve@mitre.org"},{"url":"https://bugs.python.org/issue35121","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2019/08/msg00022.html","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2019/08/msg00040.html","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/COATURTCY7G67AYI6UDV5B2JZTBCKIDX/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K7HNVIFMETMFWWWUNTB72KYJYXCZOS5V/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBTGPBUABGXZ7WH7677OEM3NSP6ZEA76/","label":"cve@mitre.org"},{"url":"https://python-security.readthedocs.io/vuln/cookie-domain-check.html","label":"cve@mitre.org"},{"url":"https://security.gentoo.org/glsa/202003-26","label":"cve@mitre.org"},{"url":"https://usn.ubuntu.com/4127-1/","label":"cve@mitre.org"},{"url":"https://usn.ubuntu.com/4127-2/","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpuapr2020.html","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00071.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00074.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2019:3725","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2019:3948","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugs.python.org/issue35121","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2019/08/msg00022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2019/08/msg00040.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/COATURTCY7G67AYI6UDV5B2JZTBCKIDX/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K7HNVIFMETMFWWWUNTB72KYJYXCZOS5V/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBTGPBUABGXZ7WH7677OEM3NSP6ZEA76/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://python-security.readthedocs.io/vuln/cookie-domain-check.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202003-26","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4127-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4127-2/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuapr2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"epss":0.0388,"epssPercentile":0.8993,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-07T18:24:08.871365Z"},"ingestedAt":"2026-10-07T18:42:20.896Z","slug":"CVE-2018-20852","body":"## Overview\n\nhttp.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into sending existing cookies to the wrong server. An attacker may abuse this flaw by using a server with a hostname that has another valid hostname as a suffix (e.g., pythonicexample.com to steal cookies for example.com). When a program uses http.cookiejar.DefaultPolicy and tries to do an HTTP connection to an attacker-controlled server, existing cookies can be leaked to the attacker. This affects 2.x through 2.7.16, 3.x before 3.4.10, 3.5.x before 3.5.7, 3.6.x before 3.6.9, and 3.7.x before 3.7.3.\n\n## Affected\n\n- `python >= 2.0, <= 2.7.16`\n- `python >= 3.0.0, < 3.4.10`\n- `python >= 3.5.0, < 3.5.7`\n- `python >= 3.6.0, < 3.6.9`\n- `python >= 3.7.0, < 3.7.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `python 3.7.3`","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.8,"exploitation":0,"ransomware":0},"changes":[]}