9.2

CVE-2026-19445

Use-after-free of a server-side SSLContext when sni_callback switches contexts

A remote, unauthenticated TLS client can make a server crash or call
through a freed pointer if its sni_callback assigns a different context to
SSLSocket.context (the documented way to select a certificate per server
name) and nothing else keeps the original ssl.SSLContext alive. Typical
cases are servers that create an SSLContext per connection or replace it
while connections are open; servers that wrap their listening socket with
it are not affected.


Mitigation: keep a reference to every SSLContext that sets sni_callback for
the lifetime of the server. TLS clients are not affected.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPython Software Foundation
≫
Produkt CPython
Default Statusunaffected
Version 0
Version < 3.10.22
Status affected
Version 3.11.0
Version < 3.11.17
Status affected
Version 3.12.0
Version < 3.12.15
Status affected
Version 3.13.0
Version < 3.13.16
Status affected
Version 3.14.0
Version < 3.14.8
Status affected
Version 3.15.0a1
Version < 3.15.0rc3
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.43% 0.349
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cna@python.org 9.2 0 0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

https://github.com/python/cpython/pull/158504
https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/
https://github.com/python/cpython/issues/156293
http://www.openwall.com/lists/oss-security/2026/09/30/17
https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d
https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b
https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7
https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698
https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c
https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8
https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b