7.6
CVE-2026-19553
- EPSS 0.4%
- Veröffentlicht 30.09.2026 16:17:39
- Zuletzt bearbeitet 03.10.2026 01:17:25
- Erkennungen
SSLContext.wrap_bio() missing validation of server_hostname parameter
ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification would be silently skipped. This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with SSLContext.check_hostname = True and no ValueError being raised due to misconfiguration. If the program passes a server_hostname value that isn't an empty string or None to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability. Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-None and non-empty server_hostname value to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a ValueError, similar to SSLContext.wrap_socket(), when server_hostname isn't supplied.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPython Software Foundation
≫
Produkt
CPython
Default Statusunaffected
Version
0
Version <
3.10.22
Status
affected
Version
3.11.0
Version <
3.11.17
Status
affected
Version
3.12.0
Version <
3.12.15
Status
affected
Version
3.13.0
Version <
3.13.16
Status
affected
Version
3.14.0
Version <
3.14.8
Status
affected
Version
3.15.0a1
Version <
3.15.0rc3
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.4% | 0.32 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cna@python.org | 7.6 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-297 Improper Validation of Certificate with Host Mismatch
The product communicates with a host that provides a certificate, but the product does not properly ensure that the certificate is actually associated with that host.
https://github.com/python/cpython/pull/158503
https://github.com/python/cpython/issues/156793
https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/
http://www.openwall.com/lists/oss-security/2026/09/30/16
https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96
https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082
https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced
https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062
https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed
https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf
https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80