Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2019-5010
n/a Python — An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6.
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U N N H 7.5 .2074 97.5 —
AFFECTED
Product Versions Fixed
Python Python.org CPython 2.7.11 Python.org CPython 3.6.6 Python.org CPython 3.5.2 Python.org CPython 3 master at 480833808e918a1dcebbbcfd07d5a8de3c5c2a66 – —
TIMELINE
Jan 4 Reserved by talos
Oct 31 Published (CNA: talos)
Oct 7 EXPLOIT PUBLISHED — CVE-2019-5010 (Python). Public exploit reference added.
Oct 7 RESCORED — CVE-2019-5010 (Python). CVSS 5.9 → 7.5 (NVD).
Description
An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability.
Lifecycle
Complete event history — 4 events, chronological
| Date | Event | Detail |
| January 4, 2019 | Reserved | Reserved by talos |
| October 31, 2019 | Published | Published (CNA: talos) |
| October 7, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2019-5010 (Python). Public exploit reference added. |
| October 7, 2026 | RESCORED | RESCORED — CVE-2019-5010 (Python). CVSS 5.9 → 7.5 (NVD). |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| n/a | Python | — | Python.org CPython 2.7.11 Python.org CPython 3.6.6 Python.org CPython 3.5.2 Python.org CPython 3 master at 480833808e918a1dcebbbcfd07d5a8de3c5c2a66 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2019-5010 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, October 8, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.