---
id: CVE-2019-16056
title: >-
  An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x
  through 3.6.9, and 3.7.x through 3.7.4
summary: >-
  An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x
  through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email
  addresses that contain multiple @ characters. An application that uses the
  email mod…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-20
vendor: python
product: python
affected:
  - python <= 2.7.16
  - 'python >= 3.0.0, <= 3.0.1'
  - 'python >= 3.1.0, <= 3.1.5'
  - 'python >= 3.2.0, <= 3.2.6'
  - 'python >= 3.3.0, <= 3.3.7'
  - 'python >= 3.4.0, <= 3.4.10'
  - 'python >= 3.5.0, <= 3.5.7'
  - 'python >= 3.6.0, <= 3.6.9'
  - 'python >= 3.7.0, <= 3.7.4'
  - fedora = 29
  - fedora = 30
  - fedora = 31
  - debian_linux = 8.0
  - debian_linux = 9.0
  - ubuntu_linux = 12.04
  - ubuntu_linux = 14.04
  - ubuntu_linux = 16.04
  - ubuntu_linux = 18.04
  - ubuntu_linux = 19.04
  - software_collections = 1.0
  - 'communications_operations_monitor >= 4.1, <= 4.3'
  - communications_operations_monitor = 3.4
  - peoplesoft_enterprise_peopletools = 8.57
  - peoplesoft_enterprise_peopletools = 8.58
  - zfs_storage_appliance_kit = 8.8
  - solaris = 11
  - leap = 15.0
  - leap = 15.1
published: '2019-09-06'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:17:12.280'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-16056'
references:
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00062.html'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00063.html'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00012.html'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00021.html'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:3725'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:3948'
    label: cve@mitre.org
  - url: 'https://bugs.python.org/issue34155'
    label: cve@mitre.org
  - url: >-
      https://github.com/python/cpython/commit/8cb65d1381b027f0b09ee36bfed7f35bb4dec9a9
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2019/09/msg00018.html'
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2019/09/msg00019.html'
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html'
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html'
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEARDOTXCYPYELKBD2KWZ27GSPXDI3GQ/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/COATURTCY7G67AYI6UDV5B2JZTBCKIDX/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E2HP37NUVLQSBW3J735A2DQDOZ4ZGBLY/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ER6LONC2B2WYIO56GBQUDU6QTWZDPUNQ/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K4KZEFP6E4YPYB52AF4WXCUDSGQOTF37/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K7HNVIFMETMFWWWUNTB72KYJYXCZOS5V/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NF3DRDGMVIRYNZMSLJIHNW47HOUQYXVG/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OYGESQSGIHDCIGOBVF7VXCMIE6YDWRYB/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QASRD4E2G65GGEHYKVHYCXB2XWAGTNL4/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QP46PQSUKYPGWTADQ67NOV3BUN6JM34Z/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SDQQ56P7ZZR64XV5DUVWNSNXKKEXUG2J/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBTGPBUABGXZ7WH7677OEM3NSP6ZEA76/
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20190926-0005/'
    label: cve@mitre.org
  - url: 'https://usn.ubuntu.com/4151-1/'
    label: cve@mitre.org
  - url: 'https://usn.ubuntu.com/4151-2/'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuapr2020.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2020.html'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00062.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00063.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00012.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:3725'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:3948'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugs.python.org/issue34155'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/python/cpython/commit/8cb65d1381b027f0b09ee36bfed7f35bb4dec9a9
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2019/09/msg00018.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2019/09/msg00019.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEARDOTXCYPYELKBD2KWZ27GSPXDI3GQ/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/COATURTCY7G67AYI6UDV5B2JZTBCKIDX/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E2HP37NUVLQSBW3J735A2DQDOZ4ZGBLY/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ER6LONC2B2WYIO56GBQUDU6QTWZDPUNQ/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K4KZEFP6E4YPYB52AF4WXCUDSGQOTF37/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K7HNVIFMETMFWWWUNTB72KYJYXCZOS5V/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NF3DRDGMVIRYNZMSLJIHNW47HOUQYXVG/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OYGESQSGIHDCIGOBVF7VXCMIE6YDWRYB/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QASRD4E2G65GGEHYKVHYCXB2XWAGTNL4/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QP46PQSUKYPGWTADQ67NOV3BUN6JM34Z/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SDQQ56P7ZZR64XV5DUVWNSNXKKEXUG2J/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBTGPBUABGXZ7WH7677OEM3NSP6ZEA76/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20190926-0005/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4151-1/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4151-2/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuapr2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
  - score-dispute
epss: 0.05366
epssPercentile: 0.92427
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-07T18:12:26.291451Z'
scores:
  nvd: 7.5
  adp: 5.3
ingestedAt: '2026-10-07T18:42:20.900Z'
---

## Overview

An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and implements some kind of checks on the From/To headers of a message could be tricked into accepting an email address that should be denied. An attack may be the same as in CVE-2019-11340; however, this CVE applies to Python more generally.

## Affected

- `python <= 2.7.16`
- `python >= 3.0.0, <= 3.0.1`
- `python >= 3.1.0, <= 3.1.5`
- `python >= 3.2.0, <= 3.2.6`
- `python >= 3.3.0, <= 3.3.7`
- `python >= 3.4.0, <= 3.4.10`
- `python >= 3.5.0, <= 3.5.7`
- `python >= 3.6.0, <= 3.6.9`
- `python >= 3.7.0, <= 3.7.4`
- `fedora = 29`
- `fedora = 30`
- `fedora = 31`
- `debian_linux = 8.0`
- `debian_linux = 9.0`
- `ubuntu_linux = 12.04`
- `ubuntu_linux = 14.04`
- `ubuntu_linux = 16.04`
- `ubuntu_linux = 18.04`
- `ubuntu_linux = 19.04`
- `software_collections = 1.0`
- `communications_operations_monitor >= 4.1, <= 4.3`
- `communications_operations_monitor = 3.4`
- `peoplesoft_enterprise_peopletools = 8.57`
- `peoplesoft_enterprise_peopletools = 8.58`
- `zfs_storage_appliance_kit = 8.8`
- `solaris = 11`
- `leap = 15.0`
- `leap = 15.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
