Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-10160

33
FAUCET Score

CVE-2019-10160 is a critical security regression in Python, affecting versions 2.7, 3.5, 3.6, 3.7, and specific 3.8 beta releases, as well as products from Canonical, Debian, Fedora, NetApp, OpenSUSE, and Red Hat. This flaw allows attackers to manipulate user-supplied URLs, potentially redirecting sensitive host-related information like cookies or authentication credentials to an attacker-controlled destination. With a CVSS score of 9.8 (CRITICAL), it presents a high risk due to its network-based attack vector, low attack complexity, and potential for high confidentiality, integrity, and availability impacts. While no active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion has been observed, its high severity warrants immediate attention.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.7.0, < 2.7.17CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.5.0, < 3.5.8CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.6.0, < 3.6.9CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.7.0, < 3.7.4CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
3.8.0CPE matchmatch criteria
cpe:2.3:a:python:python:3.8.0:alpha4:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

9.8CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
5.42%
Probability of exploitation in next 30 days
EPSS Percentile
91.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0542 is in the 86th percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (14)

github_advisorypatch availablevia nvd_reference
View patch
nodejspatch availablevia llm_extracted
View patch
pjsippatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: python27-python-0:2.7.16-6.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSFixed in: python27-python-0:2.7.16-6.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: python27-python-0:2.7.16-6.el7
View patch
redhatpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 7Fixed in: imgbased-0:1.1.9-0.1.el7ev
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 7Fixed in: ovirt-node-ng-0:4.3.5-0.20190717.0.el7ev
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 7Fixed in: redhat-release-virtualization-host-0:4.3.5-2.el7ev
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 7Fixed in: redhat-virtualization-host-0:4.3.5-20190722.0.el7_7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: python27-python-0:2.7.16-6.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: python-0:2.7.5-80.el7_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: python27-python-0:2.7.16-6.el6
View patch

Vendor Advisories (3)

nodejsllm-nodejs-302528ae26f0d946CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
pjsipllm-pjsip-7ba3ec379210ac70CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
redhatCVE-2019-10160Important

python: regression of CVE-2019-9636 due to functional fix to allow port numbers in netloc

Jun 3, 2019

References

lists.opensuse.org / opensuse-security-announce/2019-08/msg00042.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2020-01/msg00040.html
Mailing ListThird Party Advisory
access.redhat.com / errata/RHSA-2019:1587
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1700
Third Party Advisory
access.redhat.com / errata/RHSA-2019:2437
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingPatchThird Party Advisory
github.com / python/cpython/commit/250b62acc59921d399f0db47db3b462cd6037e09
PatchThird Party Advisory
github.com / python/cpython/commit/8d0ef0b5edeae52960c7ed05ae8a12388324f87e
PatchThird Party Advisory
github.com / python/cpython/commit/f61599b050c621386a3fc6bc480359e2d3bb93de
PatchThird Party Advisory
github.com / python/cpython/commit/fd1771dbdd28709716bd531580c40ae5ed814468
PatchThird Party Advisory
lists.apache.org / thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
lists.debian.org / debian-lts-announce/2019/06/msg00022.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2020/07/msg00011.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2020/08/msg00034.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/2ORNTF62QPLMJXIQ7KTZQ2776LMIXEKL
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/44TS66GJMO5H3RLMVZEBGEFTB6O2LJJU
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/E2HP37NUVLQSBW3J735A2DQDOZ4ZGBLY
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/ER6LONC2B2WYIO56GBQUDU6QTWZDPUNQ
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/NF3DRDGMVIRYNZMSLJIHNW47HOUQYXVG
python-security.readthedocs.io / vuln/urlsplit-nfkc-normalization2.html
PatchThird Party Advisory
security.netapp.com / advisory/ntap-20190617-0003
Third Party Advisory
usn.ubuntu.com / 4127-1
Third Party Advisory
usn.ubuntu.com / 4127-2
Third Party Advisory