Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1834-1 | python2.7 security update |
Debian DLA |
DLA-1835-1 | python3.4 security update |
Debian DLA |
DLA-2280-1 | python3.5 security update |
Debian DLA |
DLA-2337-1 | python2.7 security update |
EUVD |
EUVD-2019-19005 | Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that are cached against a given hostname). The components are: urllib.parse.urlsplit, urllib.parse.urlparse. The attack vector is: A specially crafted URL could be incorrectly parsed to locate cookies or authentication data and send that information to a different host than when parsed correctly. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.7, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.3, v3.7.3rc1, v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9. |
Ubuntu USN |
USN-4127-1 | Python vulnerabilities |
Ubuntu USN |
USN-4127-2 | Python vulnerabilities |
Ubuntu USN |
USN-6891-1 | Python vulnerabilities |
Wed, 07 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-173 | |
| Metrics |
cvssV3_1
|
ssvc
|
Subscriptions
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-07T18:21:37.333Z
Reserved: 2019-03-08T00:00:00.000Z
Link: CVE-2019-9636
Updated: 2024-08-04T21:54:45.131Z
Status : Modified
Published: 2019-03-08T21:29:00.703
Modified: 2026-10-07T19:17:14.490
Link: CVE-2019-9636
OpenCVE Enrichment
No data.
-
CWE-172
Encoding Error
-
CWE-173
Improper Handling of Alternate Encoding
- NVD-CWE-noinfo
Debian DLA
EUVD
Ubuntu USN