High severity7.5NVD Advisory· Published Nov 26, 2019· Updated Jun 17, 2026
CVE-2019-19274
CVE-2019-19274
Description
typed_ast 1.3.0 and 1.3.1 has a handle_keywordonly_args out-of-bounds read. An attacker with the ability to cause a Python interpreter to parse Python source (but not necessarily execute it) may be able to crash the interpreter process. This could be a concern, for example, in a web-based service that parses (but does not execute) Python code. (This issue also affected certain Python 3.8.0-alpha prereleases.)
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
typed-astPyPI | >= 1.3.0, < 1.3.2 | 1.3.2 |
Affected products
6cpe:2.3:a:python:typed_ast:1.3.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:python:typed_ast:1.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:python:typed_ast:1.3.1:*:*:*:*:*:*:*
- typed_ast/typed_astdescription
- ghsa-coords3 versionspkg:pypi/typed-astpkg:rpm/opensuse/python-typed-ast&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/python-typed-ast&distro=SUSE%20Package%20Hub%2015%20SP1
>= 1.3.0, < 1.3.2+ 2 more
- (no CPE)range: >= 1.3.0, < 1.3.2
- (no CPE)range: < 1.3.1-lp151.2.6.1
- (no CPE)range: < 1.3.1-bp151.2.6.1
Patches
Vulnerability mechanics
References
10- bugs.python.org/issue36495nvdPatchVendor AdvisoryWEB
- github.com/python/cpython/commit/a4d78362397fc3bced6ea80fbc7b5f4827aec55envdPatchThird Party AdvisoryWEB
- github.com/python/cpython/commit/dcfcd146f8e6fc5c2fc16a4c192a0c5f5ca8c53cnvdPatchThird Party AdvisoryWEB
- github.com/python/typed_ast/commit/156afcb26c198e162504a57caddfe0acd9ed7dcenvdPatchThird Party AdvisoryWEB
- github.com/python/typed_ast/commit/dc317ac9cff859aa84eeabe03fb5004982545b3bnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-m3jw-62m7-jjcmghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-19274ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/typed-ast/PYSEC-2019-130.yamlghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/LG5H4Q6LFVRX7SFXLBEJMNQFI4T5SCEAghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LG5H4Q6LFVRX7SFXLBEJMNQFI4T5SCEA/nvd
News mentions
0No linked articles in our index yet.