9.2
CVE-2026-19445
- EPSS 0.43%
- Veröffentlicht 30.09.2026 16:16:04
- Zuletzt bearbeitet 03.10.2026 01:17:24
- Erkennungen
Use-after-free of a server-side SSLContext when sni_callback switches contexts
A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open; servers that wrap their listening socket with it are not affected. Mitigation: keep a reference to every SSLContext that sets sni_callback for the lifetime of the server. TLS clients are not affected.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPython Software Foundation
≫
Produkt
CPython
Default Statusunaffected
Version
0
Version <
3.10.22
Status
affected
Version
3.11.0
Version <
3.11.17
Status
affected
Version
3.12.0
Version <
3.12.15
Status
affected
Version
3.13.0
Version <
3.13.16
Status
affected
Version
3.14.0
Version <
3.14.8
Status
affected
Version
3.15.0a1
Version <
3.15.0rc3
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.43% | 0.349 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cna@python.org | 9.2 | 0 | 0 |
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-416 Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
https://github.com/python/cpython/pull/158504
https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/
https://github.com/python/cpython/issues/156293
http://www.openwall.com/lists/oss-security/2026/09/30/17
https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d
https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b
https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7
https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698
https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c
https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8
https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b