{"id":"CVE-2019-15149","details":"core.py in Mitogen before 0.2.8 has a typo that drops the unidirectional-routing protection mechanism in the case of a child that is initiated by another child. The Ansible extension is unaffected. NOTE: the vendor disputes this issue because it is exploitable only in conjunction with hypothetical other factors, i.e., an affected use case within a library caller, and a bug in the message receiver policy code that led to reliance on this extra protection mechanism","aliases":["GHSA-8rf6-w2mx-4xjh","PYSEC-2019-104"],"modified":"2026-03-14T01:43:45.051702Z","published":"2019-08-18T20:15:09.220Z","references":[{"type":"ADVISORY","url":"https://mitogen.networkgenomics.com/changelog.html#v0-2-8-2019-08-18"},{"type":"FIX","url":"https://github.com/dw/mitogen/commit/5924af1566763e48c42028399ea0cd95c457b3dc"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mitogen-hq/mitogen","events":[{"introduced":"0"},{"fixed":"706a94bc970639a14225ce4fcc7e9a1089e718e3"},{"fixed":"5924af1566763e48c42028399ea0cd95c457b3dc"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"0.2.8"}]}}],"versions":["v0.2.0","v0.2.1","v0.2.2","v0.2.3","v0.2.4","v0.2.5","v0.2.6","v0.2.7"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-15149.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}