← Vulnerability feed

Vulnerability record · CVE-2019-19844 · published 18 December 2019

CVE-2019-19844: Django password reset allows account takeover via Unicode email collision

Djangoproject · Django

Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 mishandles password reset email matching. An attacker can supply an email address that, after Unicode case transformation, equals an existing user's address, causing the reset token to be sent to the attacker. This enables full account takeover of the matched user.

9.8 CVSS 3.1 Critical EPSS 54% · top 1.0% CWE-640 · Weak password recovery
9.8CVSS 3.1 base score, v2 5.0
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
20References
17 Jun 2026Last modified by NVD

Description

Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an attacker to be sent a password reset token for the matched user account. (One mitigation in the new releases is to send password reset tokens only to the registered user email address.)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required and a direct path to full account takeover, though no KEV listing or confirmed in-the-wild exploitation is documented.

What it is

Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 mishandles password reset email matching. An attacker can supply an email address that, after Unicode case transformation, equals an existing user's address, causing the reset token to be sent to the attacker. This enables full account takeover of the matched user.

Impact

An attacker gains a valid password reset token for another user's account and can set a new password, taking over that account. Depending on the application, this can lead to full compromise of the victim's data and privileges.

Attack surface

Reachable over the network through the password reset request endpoint; no authentication is required and no user interaction beyond the victim's email address being known or guessable. The CVSS vector confirms AV:N/AC:L/PR:N/UI:N.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.536 probability, 98.9th percentile), and public references include a Packet Storm account hijack writeup, indicating exploit knowledge is available.

What to do

  • Upgrade Django to 1.11.27, 2.2.9, 3.0.1 or later; apply the distribution backport (Ubuntu USN-4224-1, Debian DSA-4598, Gentoo GLSA 202004-17) if you cannot upgrade upstream.
  • Ensure password reset tokens are sent only to the registered user email address, as the fixed releases do.
  • Normalize and strictly compare email addresses on the server side rather than relying on case-insensitive Unicode matching.
  • Audit accounts for unexpected password resets and force credential rotation where suspicious resets occurred.
  • Monitor vendor advisories for any further Django password reset fixes.

Detection

  • Review password reset request logs for multiple requests using email variants that differ only by Unicode case or lookalike characters.
  • Alert on password reset completions where the requesting source IP or user agent differs from the account's normal pattern.
  • Search application logs for reset tokens issued to addresses that do not exactly match the stored account email.
  • Correlate spikes in password reset requests with subsequent successful logins from new IPs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-19844 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-11651SaltStack Salt master authentication bypass in ClearFuncsSaltStack Salt before 2019.2.4 and 3000 before 3000.2 fails to properly validate method calls in the salt-master ClearFuncs class, allowing remote un…KEVEPSS 97%analysed9.8CVE-2020-7247OpenSMTPD MAIL FROM command injection allows remote root code executionOpenSMTPD 6.6, as shipped in OpenBSD 6.6 and other products, mishandles input validation in smtp_mailaddr in smtp_session.c, returning an incorrect v…KEVEPSS 99%analysed9.8CVE-2019-11043PHP-FPM buffer overflow enables remote code executionPHP-FPM in certain configurations writes past allocated buffers into FCGI protocol data space, an out-of-bounds write (CWE-787, CWE-120). It affects …KEVEPSS 100%analysed9.8CVE-2019-16928Exim heap buffer overflow in string_vformat via long EHLO commandExim 4.92 through 4.92.2 contains a heap-based buffer overflow in string_vformat in string.c triggered by a long EHLO command, allowing remote code e…KEVEPSS 42%analysed9.8CVE-2019-10149Exim MTA improper recipient validation leads to remote command executionExim versions 4.87 through 4.91 fail to properly validate recipient addresses in the deliver_message() function in /src/deliver.c, allowing command i…KEVEPSS 100%analysed9.8CVE-2018-6789Exim SMTP base64d buffer overflow allows remote code executionExim before 4.90.1 contains a buffer overflow in the base64d function of its SMTP listener. A handcrafted message can trigger the overflow, and the f…KEVEPSS 82%analysed9.8CVE-2016-8735Apache Tomcat JmxRemoteLifecycleListener remote code executionApache Tomcat's JmxRemoteLifecycleListener was not updated to match the Oracle CVE-2016-3427 credential-type fix, leaving a deserialization weakness …KEVEPSS 90%analysed9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed

Source: NIST National Vulnerability Database (record CVE-2019-19844), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.