CVE-2019-9636: Canonical Ubuntu Linux

Critical severity, CVSS 9.8. EPSS: 7.7% chance of exploitation in the next 30 days.

Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that are cached against a given hostname). The components are: urllib.parse.urlsplit, urllib.parse.urlparse. The attack vector is: A specially crafted URL could be incorrectly parsed to locate cookies or authentication data and send that information to a different host than when parsed correctly. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.7, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.3, v3.7.3rc1, v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only; version 19.04 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Fedoraproject Fedora: version 28 only; version 29 only; version 30 only; version 31 only
  • Opensuse Leap: version 15.0 only; version 15.1 only; version 42.3 only
  • Oracle Sun ZFS Storage Appliance Kit: version 8.8.6 only
  • Python Python: from 2.7.0, before 2.7.17 (fixed in 2.7.17); from 3.0.0, before 3.4.10 (fixed in 3.4.10); from 3.5.0, before 3.5.7 (fixed in 3.5.7); from 3.6.0, before 3.6.9 (fixed in 3.6.9); from 3.7.0, before 3.7.3 (fixed in 3.7.3)
  • Red Hat Enterprise Linux: version 7.5 only; version 8.0 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Eus: version 7.5 only; version 8.1 only; version 8.2 only; version 8.4 only; version 8.6 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.4 only; version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux Server Eus: version 5.6 only
  • Red Hat Enterprise Linux Server Tus: version 7.4 only; version 8.2 only; version 8.4 only; version 8.6 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only
  • Red Hat Openshift Container Platform: version 3.11 only
  • Red Hat Virtualization: version 4.0 only

Published 2019-03-08. Last modified 2026-10-07.