← Vulnerability feed

Vulnerability record · CVE-2020-27619 · published 22 October 2020

CVE-2020-27619: Python vulnerability

Python · Python

In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.

9.8 CVSS 3.1 Critical EPSS 8.3% · top 5.2%
9.8CVSS 3.1 base score, v2 7.5
8.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
28References
17 Jun 2026Last modified by NVD

Description

In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://bugs.python.org/issue41944 Issue TrackingPatchVendor Advisory
https://github.com/python/cpython/commit/2ef5caa58febc8968e670e39e3d37cf8eef3cab8 PatchVendor Advisory
https://github.com/python/cpython/commit/43e523103886af66d6c27cd72431b5d9d14cd2a9 PatchVendor Advisory
https://github.com/python/cpython/commit/6c6c256df3636ff6f6136820afaefa5a10a3ac33 PatchVendor Advisory
https://github.com/python/cpython/commit/b664a1df4ee71d3760ab937653b10997081b1794 PatchVendor Advisory
https://github.com/python/cpython/commit/e912e945f2960029d039d3390ea08835ad39374b PatchVendor Advisory
https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.ap
https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.ap
https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RSLQD5CCM75IZGAMBDGUZEA
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGIY6I4YS3WOXAK4SXKIEOC
https://security.gentoo.org/glsa/202402-04
https://security.netapp.com/advisory/ntap-20201123-0004/ Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html PatchThird Party Advisory
https://bugs.python.org/issue41944 Issue TrackingPatchVendor Advisory
https://github.com/python/cpython/commit/2ef5caa58febc8968e670e39e3d37cf8eef3cab8 PatchVendor Advisory
https://github.com/python/cpython/commit/43e523103886af66d6c27cd72431b5d9d14cd2a9 PatchVendor Advisory
https://github.com/python/cpython/commit/6c6c256df3636ff6f6136820afaefa5a10a3ac33 PatchVendor Advisory
https://github.com/python/cpython/commit/b664a1df4ee71d3760ab937653b10997081b1794 PatchVendor Advisory
https://github.com/python/cpython/commit/e912e945f2960029d039d3390ea08835ad39374b PatchVendor Advisory
https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.ap
https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.ap
https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RSLQD5CCM75IZGAMBDGUZEA
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGIY6I4YS3WOXAK4SXKIEOC
https://security.gentoo.org/glsa/202402-04
https://security.netapp.com/advisory/ntap-20201123-0004/ Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html PatchThird Party Advisory

Track CVE-2020-27619 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2022-22947Spring Cloud Gateway Actuator endpoint code injectionSpring Cloud Gateway versions before 3.1.1+ and 3.0.7+ allow code injection when the Gateway Actuator endpoint is enabled, exposed and unsecured. A c…KEVEPSS 98%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2024-4577PHP-CGI on Windows argument injection leads to remote code executionPHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windo…KEVEPSS 100%analysed9.8CVE-2022-22963Spring Cloud Function routing expression SpEL injection RCESpring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions allow a user to supply a crafted SpEL expression as a routing-expression w…KEVEPSS 100%analysed9.8CVE-2022-22965Spring Framework data binding remote code execution (Spring4Shell)Spring MVC and Spring WebFlux applications on JDK 9+ can be exploited through data binding to achieve remote code execution. The known exploit path r…KEVEPSS 100%analysed9.8CVE-2021-44026Roundcube Webmail SQL injection via search parametersRoundcube Webmail before 1.3.17 and 1.4.x before 1.4.12 is prone to SQL injection through the search or search_params input. The flaw is remotely rea…KEVEPSS 70%analysed9.8CVE-2021-42013Apache HTTP Server path traversal and RCE via incomplete fixThe fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient, leaving a path traversal flaw that lets attackers map URLs to files outside…KEVEPSS 100%analysed9.8CVE-2021-41773Apache HTTP Server 2.4.49 path traversal and RCEA path normalization flaw introduced in Apache HTTP Server 2.4.49 lets attackers map URLs to files outside directories configured by Alias-like direc…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2020-27619), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.