PT-2026-103460 · Python · Cpython
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined. (affected versions not specified)
Description
A remote, unauthenticated TLS client can cause a server to crash or trigger a use-after-free condition (where the system attempts to use a memory pointer after it has been freed) if the
sni callback assigns a different context to SSLSocket.context and the original ssl.SSLContext is not kept alive. This typically occurs in servers that replace the context while connections are open or create an SSLContext per connection. Servers that wrap their listening socket are not affected.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Keep a reference to every
SSLContext that sets sni callback for the lifetime of the server.Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cpython