CVE-2019-10751
Status: ModifiedHigh (8.8)—
All versions of the HTTPie package prior to version 1.0.3 are vulnerable to Open Redirect that allows an attacker to write an arbitrary file with supplied filename and content to the current directory, by redirecting a request from HTTP to a crafted URL pointing to a server in his or hers control.
CVSS
- Version: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Base score: 8.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 2.04%
- Percentile among all scored CVEs: 80
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-601
References
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00022.html
- https://github.com/jakubroztocil/httpie/releases/tag/1.0.3
- https://lists.debian.org/debian-lts-announce/2019/09/msg00031.html
- https://snyk.io/vuln/SNYK-PYTHON-HTTPIE-460107
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00022.html
- https://github.com/jakubroztocil/httpie/releases/tag/1.0.3
- https://lists.debian.org/debian-lts-announce/2019/09/msg00031.html
- https://snyk.io/vuln/SNYK-PYTHON-HTTPIE-460107
Raw JSON (NVD)
Show
{
"id": "CVE-2019-10751",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "report@snyk.io",
"affectedData": [
{
"vendor": "n/a",
"product": "HTTPIE",
"versions": [
{
"status": "affected",
"version": "All versions prior to version 1.0.3"
}
]
}
]
}
],
"published": "2019-08-23T17:15:13.543",
"references": [
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00003.html",
"source": "report@snyk.io"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00022.html",
"source": "report@snyk.io"
},
{
"url": "https://github.com/jakubroztocil/httpie/releases/tag/1.0.3",
"tags": [
"Release Notes",
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2019/09/msg00031.html",
"source": "report@snyk.io"
},
{
"url": "https://snyk.io/vuln/SNYK-PYTHON-HTTPIE-460107",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00003.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00022.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/jakubroztocil/httpie/releases/tag/1.0.3",
"tags": [
"Release Notes",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2019/09/msg00031.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://snyk.io/vuln/SNYK-PYTHON-HTTPIE-460107",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-601"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "All versions of the HTTPie package prior to version 1.0.3 are vulnerable to Open Redirect that allows an attacker to write an arbitrary file with supplied filename and content to the current directory, by redirecting a request from HTTP to a crafted URL pointing to a server in his or hers control."
},
{
"lang": "es",
"value": "Todas las versiones del paquete HTTPie anteriores a la versión 1.0.3 son vulnerables a Open Redirect que permite a un atacante escribir un archivo arbitrario con el nombre de archivo y el contenido proporcionados al directorio actual, redireccionando una solicitud de HTTP a una URL diseñada que apunta a una servidor en su control."
}
],
"lastModified": "2026-06-17T02:11:36.103",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:httpie:httpie:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A179071-37D3-47AA-B1D7-4FD6D4D339E0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "report@snyk.io"
}