PT-2026-105786 · Pypi · Anyio

Publicado

2026-10-01

·

Atualizado

2026-10-01

CVSS v4.0

9.3

Crítica

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Impact

Services using internationalized (non-ASCII) domain names are potentially vulnerable to TLS connections made from AnyIO's connect tcp() or directly via TLSStream.wrap() where the connection has (through other means) been hijacked and redirected to a malicious server. The attacker would obtain a legitimate certificate using the IDNA 2003 encoded version of the domain name and offer it to the connecting client, making the certificate validate properly on the client's end.

Patches

The vulnerability will be patched in v4.14.2.

Workarounds

Encode host names via the idna package prior to connecting.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

PYSEC-2026-4025

Produtos afetados

Anyio