---
id: CVE-2019-5010
title: >-
  An exploitable denial-of-service vulnerability exists in the X509 certificate
  parser of Python.org Python 2.7.11 / 3.6.6
summary: >-
  An exploitable denial-of-service vulnerability exists in the X509 certificate
  parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509
  certificate can cause a NULL pointer dereference, resulting in a denial of
  service. An att…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-476
vendor: python
product: python
affected:
  - 'python >= 2.7.0, < 2.7.16'
  - 'python >= 3.4.0, < 3.4.10'
  - 'python >= 3.5.0, < 3.5.7'
  - 'python >= 3.6.0, < 3.6.9'
  - 'python >= 3.7.0, < 3.7.3'
  - leap = 15.1
  - debian_linux = 9.0
  - enterprise_linux = 8.0
  - enterprise_linux_eus = 8.1
  - enterprise_linux_eus = 8.2
  - enterprise_linux_eus = 8.4
  - enterprise_linux_eus = 8.6
  - enterprise_linux_server_aus = 8.2
  - enterprise_linux_server_aus = 8.4
  - enterprise_linux_server_aus = 8.6
  - enterprise_linux_server_tus = 8.2
  - enterprise_linux_server_tus = 8.4
  - enterprise_linux_server_tus = 8.6
patched:
  - python 3.7.3
published: '2019-10-31'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:17:14.050'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-5010'
references:
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html'
    label: talos-cna@cisco.com
  - url: 'https://access.redhat.com/errata/RHSA-2019:3520'
    label: talos-cna@cisco.com
  - url: 'https://access.redhat.com/errata/RHSA-2019:3725'
    label: talos-cna@cisco.com
  - url: >-
      https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
    label: talos-cna@cisco.com
  - url: 'https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html'
    label: talos-cna@cisco.com
  - url: 'https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html'
    label: talos-cna@cisco.com
  - url: 'https://security.gentoo.org/glsa/202003-26'
    label: talos-cna@cisco.com
  - url: 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0758'
    label: talos-cna@cisco.com
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:3520'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:3725'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202003-26'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://talosintelligence.com/vulnerability_reports/TALOS-2019-0758'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
  - exploit-available
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-07T18:55:12.122902Z'
scores:
  nvd: 7.5
  cna: 5.9
epss: 0.20743
epssPercentile: 0.97478
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/JonathanWilbur/CVE-2019-5010'
  checkedAt: '2026-10-07T19:44:51.101Z'
exploitAvailable: true
ingestedAt: '2026-10-07T19:44:15.637Z'
---

## Overview

An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability.

## Affected

- `python >= 2.7.0, < 2.7.16`
- `python >= 3.4.0, < 3.4.10`
- `python >= 3.5.0, < 3.5.7`
- `python >= 3.6.0, < 3.6.9`
- `python >= 3.7.0, < 3.7.3`
- `leap = 15.1`
- `debian_linux = 9.0`
- `enterprise_linux = 8.0`
- `enterprise_linux_eus = 8.1`
- `enterprise_linux_eus = 8.2`
- `enterprise_linux_eus = 8.4`
- `enterprise_linux_eus = 8.6`
- `enterprise_linux_server_aus = 8.2`
- `enterprise_linux_server_aus = 8.4`
- `enterprise_linux_server_aus = 8.6`
- `enterprise_linux_server_tus = 8.2`
- `enterprise_linux_server_tus = 8.4`
- `enterprise_linux_server_tus = 8.6`

## Remediation

Upgrade past the affected range:

- `python 3.7.3`
