python: regression of CVE-2019-9636 due to functional fix to allow port numbers in netloc
Published Jun 7, 2019
9.8
CRITICALCVSS 3.1
EPSS 5.23%
Description
A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application parses user-supplied URLs to store cookies, authentication credentials, or other kind of information, it is possible for an attacker to provide specially crafted URLs to make the application locate host-related information (e.g. cookies, authentication data) and send them to a different host than where it should, unlike if the URLs had been correctly parsed. The result of an attack may vary based on the application.
Affected products
-
- Version affects 2.7, 3.5, 3.6, 3.7, >= v3.8.0a4 and < v3.8.0b1StatusaffectedConstraints-
- Version
Configuration 1
Configuration 2
- 7.0
- 7.6
- 7.0
- 7.6
- 7.6
- 7.0
Configuration 3
- 8.0
- 9.0
Configuration 5
- 29
- 30
- 31
Configuration 6
- 12.04
- 14.04
- 16.04
- 18.04
- 19.04
Configuration 7
- 4.0
Running on/with
- 7.0
Configuration 8
- n/a
- n/a
No data.
Red Hat Enterprise Linux 7
python-0:2.7.5-80.el7_6
Fixed · RHSA-2019:1587
Red Hat Software Collections for Red Hat Enterprise Linux 6
python27-python-0:2.7.16-6.el6
Fixed · RHSA-2019:1700
Red Hat Software Collections for Red Hat Enterprise Linux 7
python27-python-0:2.7.16-6.el7
Fixed · RHSA-2019:1700
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
python27-python-0:2.7.16-6.el7
Fixed · RHSA-2019:1700
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
python27-python-0:2.7.16-6.el7
Fixed · RHSA-2019:1700
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
python27-python-0:2.7.16-6.el7
Fixed · RHSA-2019:1700
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
imgbased-0:1.1.9-0.1.el7ev
Fixed · RHSA-2019:2437
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
ovirt-node-ng-0:4.3.5-0.20190717.0.el7ev
Fixed · RHSA-2019:2437
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-release-virtualization-host-0:4.3.5-2.el7ev
Fixed · RHSA-2019:2437
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-virtualization-host-0:4.3.5-20190722.0.el7_7
Fixed · RHSA-2019:2437
Red Hat Enterprise Linux 5
python
Not affected
Red Hat Enterprise Linux 6
python
Not affected
Red Hat Enterprise Linux 7
python3
Not affected
Red Hat Enterprise Linux 8
python27:2.7/python2
Not affected
Red Hat Enterprise Linux 8
python3
Not affected
Red Hat Enterprise Linux 8
python36:3.6/python36
Not affected
Red Hat Software Collections
rh-python35-python
Out of support scope
Red Hat Software Collections
rh-python36-python
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | python-0:2.7.5-80.el7_6 | Fixed | RHSA-2019:1587 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | python27-python-0:2.7.16-6.el6 | Fixed | RHSA-2019:1700 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | python27-python-0:2.7.16-6.el7 | Fixed | RHSA-2019:1700 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | python27-python-0:2.7.16-6.el7 | Fixed | RHSA-2019:1700 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | python27-python-0:2.7.16-6.el7 | Fixed | RHSA-2019:1700 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | python27-python-0:2.7.16-6.el7 | Fixed | RHSA-2019:1700 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | imgbased-0:1.1.9-0.1.el7ev | Fixed | RHSA-2019:2437 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | ovirt-node-ng-0:4.3.5-0.20190717.0.el7ev | Fixed | RHSA-2019:2437 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-release-virtualization-host-0:4.3.5-2.el7ev | Fixed | RHSA-2019:2437 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-virtualization-host-0:4.3.5-20190722.0.el7_7 | Fixed | RHSA-2019:2437 |
| Red Hat Enterprise Linux 5 | python | Not affected | n/a |
| Red Hat Enterprise Linux 6 | python | Not affected | n/a |
| Red Hat Enterprise Linux 7 | python3 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python27:2.7/python2 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python3 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python36:3.6/python36 | Not affected | n/a |
| Red Hat Software Collections | rh-python35-python | Out of support scope | n/a |
| Red Hat Software Collections | rh-python36-python | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of python as shipped with Red Hat Enterprise Linux 5 and 6 as the security regression was not introduced in those versions. See CVE-2019-9636 for more details about the how these versions of Red Hat Enterprise Linux are affected with regard to the original flaw. This issue did not affect the versions of python as shipped with Red Hat Enterprise Linux 8 as the security regression was not introduced in those versions. See CVE-2019-9636 for more details about the how these versions of Red Hat Enterprise Linux are affected with regard to the original flaw.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (19 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 5.23% (0.05227) | 92.25th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.23% (0.05227) | 91.42th | v5 (v2026.06.15) |
| Mar 30, 2025 | 1.81% (0.01811) | 81.21th | v4 (v2025.03.14) |
| Mar 29, 2025 | 8.12% (0.08121) | 86.68th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.81% (0.01811) | 81.62th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.63% (0.00634) | 79.80th | v3 (v2023.03.01) |
| May 31, 2024 | 0.48% (0.00477) | 75.77th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.29% (0.00291) | 68.22th | v3 (v2023.03.01) |
| Dec 4, 2023 | 0.29% (0.00291) | 65.60th | v3 (v2023.03.01) |
| Sep 16, 2023 | 0.34% (0.00336) | 67.82th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.37% (0.00374) | 69.28th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.45% (0.00445) | 70.94th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.69% (0.02686) | 82.85th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.69% (0.02686) | 81.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 24.56% (0.24563) | 95.26th | v2 (v2022.01.01) |
| Feb 3, 2022 | 21.69% (0.21692) | 94.47th | v1 |
| Jan 6, 2022 | 21.69% (0.21692) | 94.41th | v1 |
| Jan 5, 2022 | 5.82% (0.05815) | 89.46th | v5 (v2026.06.15) |
| Apr 14, 2021 | 5.82% (0.05815) | 0.00th | v1 |
References (32)
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00042.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1587 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1700 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2437 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-10160 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1718388 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10160 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://github.com/python/cpython/commit/250b62acc59921d399f0db47db3b462cd6037e09 x_refsource_CONFIRMPatchThird Party Advisory
- https://github.com/python/cpython/commit/8d0ef0b5edeae52960c7ed05ae8a12388324f87e x_refsource_CONFIRMPatchThird Party Advisory
- https://github.com/python/cpython/commit/f61599b050c621386a3fc6bc480359e2d3bb93de x_refsource_CONFIRMPatchThird Party Advisory
- https://github.com/python/cpython/commit/fd1771dbdd28709716bd531580c40ae5ed814468 x_refsource_CONFIRMPatchThird Party Advisory
- https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ORNTF62QPLMJXIQ7KTZQ2776LMIXEKL/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/44TS66GJMO5H3RLMVZEBGEFTB6O2LJJU/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E2HP37NUVLQSBW3J735A2DQDOZ4ZGBLY/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ER6LONC2B2WYIO56GBQUDU6QTWZDPUNQ/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NF3DRDGMVIRYNZMSLJIHNW47HOUQYXVG/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-10160
- https://python-security.readthedocs.io/vuln/urlsplit-nfkc-normalization2.html x_refsource_MISCPatchThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190617-0003/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4127-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4127-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-10160
Change history (0)
No recorded changes yet.