Vulnerability record · CVE-2019-19844 · published 18 December 2019
CVE-2019-19844: Django password reset allows account takeover via Unicode email collision
Djangoproject · Django
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 mishandles password reset email matching. An attacker can supply an email address that, after Unicode case transformation, equals an existing user's address, causing the reset token to be sent to the attacker. This enables full account takeover of the matched user.
Description
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an attacker to be sent a password reset token for the matched user account. (One mitigation in the new releases is to send password reset tokens only to the registered user email address.)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required and a direct path to full account takeover, though no KEV listing or confirmed in-the-wild exploitation is documented.
What it is
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 mishandles password reset email matching. An attacker can supply an email address that, after Unicode case transformation, equals an existing user's address, causing the reset token to be sent to the attacker. This enables full account takeover of the matched user.
Impact
An attacker gains a valid password reset token for another user's account and can set a new password, taking over that account. Depending on the application, this can lead to full compromise of the victim's data and privileges.
Attack surface
Reachable over the network through the password reset request endpoint; no authentication is required and no user interaction beyond the victim's email address being known or guessable. The CVSS vector confirms AV:N/AC:L/PR:N/UI:N.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.536 probability, 98.9th percentile), and public references include a Packet Storm account hijack writeup, indicating exploit knowledge is available.
What to do
- Upgrade Django to 1.11.27, 2.2.9, 3.0.1 or later; apply the distribution backport (Ubuntu USN-4224-1, Debian DSA-4598, Gentoo GLSA 202004-17) if you cannot upgrade upstream.
- Ensure password reset tokens are sent only to the registered user email address, as the fixed releases do.
- Normalize and strictly compare email addresses on the server side rather than relying on case-insensitive Unicode matching.
- Audit accounts for unexpected password resets and force credential rotation where suspicious resets occurred.
- Monitor vendor advisories for any further Django password reset fixes.
Detection
- Review password reset request logs for multiple requests using email variants that differ only by Unicode case or lookalike characters.
- Alert on password reset completions where the requesting source IP or user agent differs from the account's normal pattern.
- Search application logs for reset tokens issued to addresses that do not exactly match the stored account email.
- Correlate spikes in password reset requests with subsequent successful logins from new IPs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-19844 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-19844), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.