Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-9948

27
FAUCET Score

CVE-2019-9948 is a critical vulnerability affecting the urllib module in Python 2.x versions up to 2.7.16, impacting various distributions including Debian, Fedora, and Red Hat. This flaw allows remote attackers to bypass file URI blacklists by utilizing the 'local_file:' scheme, enabling access to local files. With a CVSS score of 9.1 (CRITICAL), it presents a high risk due to its network-based attack vector, low attack complexity, and potential for complete confidentiality and integrity compromise. Despite its severity, there is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.0, < 2.7.17CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.5.0, < 3.5.8CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.6.0, < 3.6.9CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.7.0, < 3.7.4CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
15.0CPE matchmatch criteria
cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
12.26%
Probability of exploitation in next 30 days
EPSS Percentile
95.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1226 is in the 92nd percentile among its peer group of 36,897 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (27)

github_advisorypatch availablevia nvd_reference
View patch
nodejspatch availablevia llm_extracted
View patch
pjsippatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Tower 3.4 for RHEL 7Fixed in: ansible-tower-34/ansible-tower-memcached:1.4.15-28
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: python-0:2.7.5-86.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Advanced Update SupportFixed in: python-0:2.7.5-63.el7_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Telco Extended Update SupportFixed in: python-0:2.7.5-63.el7_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Update Services for SAP SolutionsFixed in: python-0:2.7.5-63.el7_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.5 Extended Update SupportFixed in: python-0:2.7.5-74.el7_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Extended Update SupportFixed in: python-0:2.7.5-83.el7_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python27:2.7-8010020190903182548.51c94b97
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3-0:3.6.8-15.1.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: python27-python-0:2.7.16-6.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: rh-python36-python-0:3.6.9-2.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: python27-python-0:2.7.16-6.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-python36-python-0:3.6.9-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSFixed in: python27-python-0:2.7.16-6.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: python27-python-0:2.7.16-6.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-python36-python-0:3.6.9-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: python27-python-0:2.7.16-6.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: rh-python36-python-0:3.6.9-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-python36-python-0:3.6.9-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Tower 3.4 for RHEL 7Fixed in: ansible-tower-35/ansible-tower-memcached:1.4.15-28
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Tower 3.4 for RHEL 7Fixed in: ansible-tower-37/ansible-tower-memcached-rhel7:1.4.15-28
View patch
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: rh-python35-python
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: python
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: python

Vendor Advisories (3)

nodejsllm-nodejs-302528ae26f0d946CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
pjsipllm-pjsip-7ba3ec379210ac70CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
redhatCVE-2019-9948Moderate

python: Undocumented local_file protocol allows remote attackers to bypass protection mechanisms

Mar 23, 2019

References

lists.opensuse.org / opensuse-security-announce/2019-04/msg00092.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-06/msg00050.html
Mailing ListThird Party Advisory
packetstormsecurity.com / files/154927/Slackware-Security-Advisory-python-Updates.html
Third Party AdvisoryVDB Entry
access.redhat.com / errata/RHSA-2019:1700
Third Party Advisory
access.redhat.com / errata/RHSA-2019:2030
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3335
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3520
Third Party Advisory
bugs.python.org / issue35907
ExploitIssue TrackingVendor Advisory
github.com / python/cpython/pull/11842
PatchThird Party Advisory
lists.apache.org / thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
lists.debian.org / debian-lts-announce/2019/06/msg00022.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2019/07/msg00011.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2020/07/msg00011.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2020/08/msg00034.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES
seclists.org / bugtraq/2019/Oct/29
Mailing ListThird Party Advisory
security.gentoo.org / glsa/202003-26
Third Party Advisory
security.netapp.com / advisory/ntap-20190404-0004
Third Party Advisory
usn.ubuntu.com / 4127-1
Third Party Advisory
usn.ubuntu.com / 4127-2
Third Party Advisory
securityfocus.com / bid/107549
Third Party AdvisoryVDB Entry