---
id: CVE-2018-20852
title: >-
  http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in
  Python before 3.7.3 does not correctly validate the domain: it can be tricked
  into sending existing cookies to the wrong server
summary: >-
  http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in
  Python before 3.7.3 does not correctly validate the domain: it can be tricked
  into sending existing cookies to the wrong server. An attacker may abuse this
  flaw by…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'
cwe:
  - CWE-20
vendor: python
product: python
affected:
  - 'python >= 2.0, <= 2.7.16'
  - 'python >= 3.0.0, < 3.4.10'
  - 'python >= 3.5.0, < 3.5.7'
  - 'python >= 3.6.0, < 3.6.9'
  - 'python >= 3.7.0, < 3.7.3'
patched:
  - python 3.7.3
published: '2019-07-13'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:17:11.553'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-20852'
references:
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00071.html'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00074.html'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:3725'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:3948'
    label: cve@mitre.org
  - url: 'https://bugs.python.org/issue35121'
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2019/08/msg00022.html'
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2019/08/msg00040.html'
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html'
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html'
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/COATURTCY7G67AYI6UDV5B2JZTBCKIDX/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K7HNVIFMETMFWWWUNTB72KYJYXCZOS5V/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBTGPBUABGXZ7WH7677OEM3NSP6ZEA76/
    label: cve@mitre.org
  - url: 'https://python-security.readthedocs.io/vuln/cookie-domain-check.html'
    label: cve@mitre.org
  - url: 'https://security.gentoo.org/glsa/202003-26'
    label: cve@mitre.org
  - url: 'https://usn.ubuntu.com/4127-1/'
    label: cve@mitre.org
  - url: 'https://usn.ubuntu.com/4127-2/'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuapr2020.html'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00071.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00074.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:3725'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:3948'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugs.python.org/issue35121'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2019/08/msg00022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2019/08/msg00040.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/COATURTCY7G67AYI6UDV5B2JZTBCKIDX/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K7HNVIFMETMFWWWUNTB72KYJYXCZOS5V/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBTGPBUABGXZ7WH7677OEM3NSP6ZEA76/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://python-security.readthedocs.io/vuln/cookie-domain-check.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202003-26'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4127-1/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4127-2/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuapr2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
epss: 0.0388
epssPercentile: 0.8993
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-07T18:24:08.871365Z'
ingestedAt: '2026-10-07T18:42:20.896Z'
---

## Overview

http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into sending existing cookies to the wrong server. An attacker may abuse this flaw by using a server with a hostname that has another valid hostname as a suffix (e.g., pythonicexample.com to steal cookies for example.com). When a program uses http.cookiejar.DefaultPolicy and tries to do an HTTP connection to an attacker-controlled server, existing cookies can be leaked to the attacker. This affects 2.x through 2.7.16, 3.x before 3.4.10, 3.5.x before 3.5.7, 3.6.x before 3.6.9, and 3.7.x before 3.7.3.

## Affected

- `python >= 2.0, <= 2.7.16`
- `python >= 3.0.0, < 3.4.10`
- `python >= 3.5.0, < 3.5.7`
- `python >= 3.6.0, < 3.6.9`
- `python >= 3.7.0, < 3.7.3`

## Remediation

Upgrade past the affected range:

- `python 3.7.3`
