← Back to browse · API

CVE-2019-17626

Severity
CRITICAL
CVSS
9.8
EPSS
0.10231
Risk score
42.78
CISA KEV
No
PoC
No
Published
2019-10-16
Modified
2024-08-05
First seen
2026-08-07
Aliases
EUVD-2019-0122, GHSA-QPG2-VX7J-3869, PYSEC-2019-117
Products
n/a:n/a n/a
Sources
euvd EUVD-2019-0122

Description

ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document with '<span color="' followed by arbitrary Python code.

References