CVE-2019-9636Critical· 9.8▾ MidnightPython 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that are cach…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 1.8 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
8.8%
5.3 → 9.8
medium → critical
Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that are cached against a given hostname). The components are: urllib.parse.urlsplit, urllib.parse.urlparse. The attack vector is: A specially crafted URL could be incorrectly parsed to locate cookies or authentication data and send that information to a different host than when parsed correctly. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.7, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.3, v3.7.3rc1, v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9.
python >= 2.7.0, < 2.7.17python >= 3.0.0, < 3.4.10python >= 3.5.0, < 3.5.7python >= 3.6.0, < 3.6.9python >= 3.7.0, < 3.7.3fedora = 28fedora = 29fedora = 30fedora = 31leap = 15.0leap = 15.1leap = 42.3debian_linux = 8.0debian_linux = 9.0ubuntu_linux = 12.04ubuntu_linux = 14.04ubuntu_linux = 16.04ubuntu_linux = 18.04ubuntu_linux = 19.04openshift_container_platform = 3.11enterprise_linux = 7.5enterprise_linux = 8.0enterprise_linux_desktop = 6.0enterprise_linux_eus = 7.5enterprise_linux_eus = 8.1enterprise_linux_eus = 8.2enterprise_linux_eus = 8.4enterprise_linux_eus = 8.6enterprise_linux_server = 6.0enterprise_linux_server_aus = 7.4enterprise_linux_server_aus = 8.2enterprise_linux_server_aus = 8.4enterprise_linux_server_eus = 5.6enterprise_linux_server_tus = 7.4enterprise_linux_server_tus = 8.2enterprise_linux_server_tus = 8.4enterprise_linux_server_tus = 8.6enterprise_linux_workstation = 6.0virtualization = 4.0sun_zfs_storage_appliance_kit = 8.8.6Upgrade past the affected range:
python 3.7.3Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2018-14647High· 7.5Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization
CVE-2019-16056High· 7.5An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4
CVE-2019-5010High· 7.5An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6
CVE-2019-9948Critical· 9.1urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/…
CVE-2019-18348Medium· 6.1An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0
CVE-2019-16935Medium· 6.1The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field