A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application parses user-supplied URLs to store cookies, authentication credentials, or other kind of information, it is possible for an attacker to provide specially crafted URLs to make the application locate host-related information (e.g. cookies, authentication data) and send them to a different host than where it should, unlike if the URLs had been correctly parsed. The result of an attack may vary based on the application.
CVE-2019-10160
Score 9.8 from GitHub Security Advisory (severity: CRITICAL) published 2022-05-24. NVD baseline CVSS 9.8; sources differ by 0.0.
- High severity, but no confirmed exploitation yet
A fix is available — apply it.
- CVSS v3
- 9.8
- EG Score
- 9.8(medium)
- EPSS
- 91.9%
- KEV
- Not listed
Published
June 7, 2019
Last Modified
November 21, 2024
Advisory Details (8)
Auto-updated Jun 8, 2026commit fd1771dbdd28 (python/cpython)
Fix landed in python/cpython commit fd1771dbdd28 — awaiting tagged release
https://github.com/python/cpython/commit/fd1771dbdd28709716bd531580c40ae5ed814468commit f61599b050c6 (python/cpython)
Fix landed in python/cpython commit f61599b050c6 — awaiting tagged release
https://github.com/python/cpython/commit/f61599b050c621386a3fc6bc480359e2d3bb93decommit 8d0ef0b5edea (python/cpython)
Fix landed in python/cpython commit 8d0ef0b5edea — awaiting tagged release
https://github.com/python/cpython/commit/8d0ef0b5edeae52960c7ed05ae8a12388324f87ecommit 250b62acc599 (python/cpython)
Fix landed in python/cpython commit 250b62acc599 — awaiting tagged release
https://github.com/python/cpython/commit/250b62acc59921d399f0db47db3b462cd6037e091718388 – (CVE-2019-10160) CVE-2019-10160 python: regression of CVE-2019-9636 due to functional fix to allow port numbers in netloc
Affected: Red Hat Enterprise Linux 5 and 6 as the security regression was not introduced in those versions. See
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10160Affected: Red Hat Enterprise Linux 7.
https://access.redhat.com/errata/RHSA-2019:2437Affected: Red Hat Enterprise Linux 7.
https://access.redhat.com/errata/RHSA-2019:1587Patch Availability(6)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| ubuntu | python3.7-venv (3.7.3-2ubuntu0.1) @ disco | 2026-05-27 | ubuntu |
| ubuntu | python2.7-minimal (2.7.3-0ubuntu3.14) @ precise | 2026-05-27 | ubuntu |
| ubuntu | python3.11-venv (3.11.0~rc1-1~22.04.1~esm1) @ jammy | 2026-05-27 | ubuntu |
| redhat | redhat-virtualization-host-0:4.3.5-20190722.0.el7_7 | 2019-08-12 | redhat |
| redhat | python27-python-0:2.7.16-6.el7 | 2019-07-08 | redhat |
| redhat | python-0:2.7.5-80.el7_6 | 2019-06-20 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Weakness Classification(2)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
All Vendor Advisories
(6)
Every vendor that published an advisory referencing this CVE — pulled from our cve_vendor_advisories aggregation. Click any row for the vendor's original advisory page.
- Red HatRHSA-2019:1587IMPORTANT2019-06-03
RHSA-2019:1587 — Important
- Red HatRHSA-2019:1700IMPORTANT2019-06-03
RHSA-2019:1700 — Important
- Red HatRHSA-2019:2437IMPORTANT2019-06-03
RHSA-2019:2437 — Important
- UbuntuUSN-4127-1MEDIUM
Python vulnerabilities
- UbuntuUSN-4127-2MEDIUM
Python vulnerabilities
- UbuntuUSN-6891-1MEDIUM
Python vulnerabilities
Data Freshness Timeline
(refreshed 12× in last 7d / 41× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-07-22 14:05 UTCEPSS rescore
- 2026-07-21 15:22 UTCEPSS rescore
- 2026-07-21 15:22 UTCEPSS rescore
- 2026-07-20 17:04 UTCEPSS rescore
- 2026-07-20 15:04 UTCOSV refresh
- 2026-07-19 14:28 UTCEPSS rescore
- 2026-07-19 14:28 UTCEPSS rescore
- 2026-07-19 02:26 UTCEPSS rescore
- 2026-07-19 02:26 UTCEPSS rescore
- 2026-07-18 10:01 UTCEPSS rescore
- 2026-07-16 16:59 UTCEPSS rescore
- 2026-07-16 16:59 UTCEPSS rescore
- 2026-07-15 16:55 UTCEPSS rescore
- 2026-07-13 22:27 UTCEPSS rescore
- 2026-07-12 05:43 UTCEPSS rescore
- 2026-07-11 08:24 UTCEPSS rescore
- 2026-07-09 19:06 UTCEPSS rescore
- 2026-07-08 15:11 UTCEPSS rescore
- 2026-07-07 13:42 UTCEPSS rescore
- 2026-07-06 16:25 UTCEPSS rescore
- 2026-07-06 02:20 UTCEPSS rescore
- 2026-07-05 02:27 UTCEPSS rescore
- 2026-07-04 06:28 UTCEPSS rescore
- 2026-07-04 06:28 UTCEPSS rescore
- 2026-07-03 10:26 UTCOSV refresh
Show 66 moreShow fewer
- 2026-07-02 16:56 UTCEPSS rescore
- 2026-07-01 15:03 UTCEPSS rescore
- 2026-07-01 15:03 UTCEPSS rescore
- 2026-06-30 23:20 UTCEPSS rescore
- 2026-06-30 23:20 UTCEPSS rescore
- 2026-06-28 14:04 UTCEPSS rescore
- 2026-06-28 04:54 UTCEPSS rescore
- 2026-06-28 04:53 UTCEPSS rescore
- 2026-06-27 03:06 UTCEPSS rescore
- 2026-06-27 03:06 UTCEPSS rescore
- 2026-06-25 13:47 UTCEPSS rescore
- 2026-06-25 13:47 UTCEPSS rescore
- 2026-06-24 14:03 UTCEPSS rescore
- 2026-06-24 14:02 UTCEPSS rescore
- 2026-06-23 21:30 UTCEPSS rescore
- 2026-06-23 21:30 UTCEPSS rescore
- 2026-06-22 14:23 UTCEPSS rescore
- 2026-06-22 14:23 UTCEPSS rescore
- 2026-06-21 14:54 UTCEPSS rescore
- 2026-06-21 14:54 UTCEPSS rescore
- 2026-06-21 01:57 UTCEPSS rescore
- 2026-06-21 01:57 UTCEPSS rescore
- 2026-06-19 19:23 UTCEPSS rescore
- 2026-06-19 19:23 UTCEPSS rescore
- 2026-06-18 17:50 UTCEPSS rescore
- 2026-06-17 17:50 UTCEPSS rescore
- 2026-06-16 17:50 UTCEPSS rescore
- 2026-06-15 17:45 UTCEPSS rescore
- 2026-06-15 00:43 UTCOSV refresh
- 2026-06-14 23:15 UTCEPSS rescore
- 2026-06-14 23:15 UTCEPSS rescore
- 2026-06-13 22:58 UTCEPSS rescore
- 2026-06-12 23:09 UTCEPSS rescore
- 2026-06-11 13:58 UTCEPSS rescore
- 2026-06-11 13:58 UTCEPSS rescore
- 2026-06-10 22:16 UTCEPSS rescore
- 2026-06-10 13:19 UTCEPSS rescore
- 2026-06-08 14:15 UTCEPSS rescore
- 2026-06-08 14:14 UTCEPSS rescore
- 2026-06-07 15:23 UTCEPSS rescore
- 2026-06-07 15:22 UTCEPSS rescore
- 2026-06-06 13:45 UTCEPSS rescore
- 2026-06-06 13:45 UTCEPSS rescore
- 2026-06-05 22:45 UTCEPSS rescore
- 2026-06-05 22:45 UTCEPSS rescore
- 2026-06-05 06:08 UTCEPSS rescore
- 2026-06-05 06:08 UTCEPSS rescore
- 2026-06-04 13:10 UTCEPSS rescore
- 2026-06-04 13:10 UTCEPSS rescore
- 2026-06-02 20:11 UTCEPSS rescore
- 2026-06-01 13:50 UTCEPSS rescore
- 2026-06-01 13:50 UTCEPSS rescore
- 2026-05-31 22:29 UTCEPSS rescore
- 2026-05-31 22:29 UTCEPSS rescore
- 2026-05-31 00:14 UTCEPSS rescore
- 2026-05-31 00:14 UTCEPSS rescore
- 2026-05-29 13:42 UTCEPSS rescore
- 2026-05-28 13:43 UTCEPSS rescore
- 2026-05-27 18:39 UTCEG score recompute
- 2026-05-27 18:39 UTCVendor advisory
- 2026-05-27 18:39 UTCGHSA enrichment
- 2026-05-27 13:38 UTCEPSS rescore
- 2026-05-26 13:42 UTCEPSS rescore
- 2026-05-26 13:42 UTCEPSS rescore
- 2026-05-26 07:17 UTCEPSS rescore
- 2026-05-26 07:17 UTCEPSS rescore
Frequently asked(5)
What is CVE-2019-10160?
When was CVE-2019-10160 disclosed?
Is CVE-2019-10160 actively exploited?
What is the CVSS score of CVE-2019-10160?
How do I remediate CVE-2019-10160?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2019-10160
Is Your Infrastructure Affected by CVE-2019-10160?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.