CVE-2019-16056: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 5.1% chance of exploitation in the next 30 days.

An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and implements some kind of checks on the From/To headers of a message could be tricked into accepting an email address that should be denied. An attack may be the same as in CVE-2019-11340; however, this CVE applies to Python more generally.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only; version 19.04 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Fedoraproject Fedora: version 29 only; version 30 only; version 31 only
  • Opensuse Leap: version 15.0 only; version 15.1 only
  • Oracle Communications Operations Monitor: from 4.1, up to and including 4.3; version 3.4 only
  • Oracle PeopleSoft Enterprise PeopleTools: version 8.57 only; version 8.58 only
  • Oracle Solaris: version 11 only
  • Oracle ZFS Storage Appliance Kit: version 8.8 only
  • Python Python: up to and including 2.7.16; from 3.0.0, up to and including 3.0.1; from 3.1.0, up to and including 3.1.5; from 3.2.0, up to and including 3.2.6; from 3.3.0, up to and including 3.3.7; from 3.4.0, up to and including 3.4.10; …
  • Red Hat Software Collections: version 1.0 only

Published 2019-09-06. Last modified 2026-10-07.