CVE-2019-16056High· 7.5▾ TwilightAn issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email mod…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 1.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
5.4%
5.3 → 7.5
medium → high
An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and implements some kind of checks on the From/To headers of a message could be tricked into accepting an email address that should be denied. An attack may be the same as in CVE-2019-11340; however, this CVE applies to Python more generally.
python <= 2.7.16python >= 3.0.0, <= 3.0.1python >= 3.1.0, <= 3.1.5python >= 3.2.0, <= 3.2.6python >= 3.3.0, <= 3.3.7python >= 3.4.0, <= 3.4.10python >= 3.5.0, <= 3.5.7python >= 3.6.0, <= 3.6.9python >= 3.7.0, <= 3.7.4fedora = 29fedora = 30fedora = 31debian_linux = 8.0debian_linux = 9.0ubuntu_linux = 12.04ubuntu_linux = 14.04ubuntu_linux = 16.04ubuntu_linux = 18.04ubuntu_linux = 19.04software_collections = 1.0communications_operations_monitor >= 4.1, <= 4.3communications_operations_monitor = 3.4peoplesoft_enterprise_peopletools = 8.57peoplesoft_enterprise_peopletools = 8.58zfs_storage_appliance_kit = 8.8solaris = 11leap = 15.0leap = 15.1Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2018-20852Medium· 4.3http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into sending existing cookies to the wrong server
CVE-2018-14647High· 7.5Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization
CVE-2019-9636Critical· 9.8Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization
CVE-2019-5010High· 7.5An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6
CVE-2019-9948Critical· 9.1urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/…
CVE-2019-18348Medium· 6.1An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0