CVE-2019-5010

Updated: 2025-08-20 00:06:33.072728

Description:

An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 5.0
CVSS Version 3.x HIGH 7.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Alpine Linux 3.22 python 3.7 7.5 HIGH Not Vulnerable 2026-02-16 14:40:25
Alpine Linux 3.22 python 3.6 7.5 HIGH Already Fixed 2026-01-27 16:43:19
Debian 10 python 3.6 7.5 HIGH Already Fixed 2025-09-05 09:16:36
Debian 10 python 2.7 7.5 HIGH Not Vulnerable 2025-09-05 09:16:34
Debian 11 python 2.7 7.5 HIGH Not Vulnerable 2025-09-05 09:16:34
Debian 11 python 3.6 7.5 HIGH Already Fixed 2025-09-05 09:16:35
Debian 12 python 3.7 7.5 HIGH Not Vulnerable 2025-11-12 16:12:41 Not vulnerable: the deployed Python is 3.7.17. CVE-2019-5010 affects CPython’s ssl X.509 certifica...
Debian 12 python 3.6 7.5 HIGH Already Fixed 2025-09-05 09:16:35 Not vulnerable: the deployed Python is 3.7.17. CVE-2019-5010 affects CPython’s ssl X.509 certifica...
Debian 12 python 2.7 7.5 HIGH Not Vulnerable 2025-09-05 09:16:33 Not vulnerable: the deployed Python is 3.7.17. CVE-2019-5010 affects CPython’s ssl X.509 certifica...
Debian 13 python 3.6 7.5 HIGH Already Fixed 2025-09-24 22:30:04
Total: 30