PT-2026-103461 · Python · Python
CVSS v4.0
7.6
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Python (affected versions not specified)
Description
The
ssl.SSLContext.wrap bio() function fails to require the server hostname argument to be non-null when ssl.SSLContext.check hostname is enabled. Due to a missing parameter check in SSLObject, if the server hostname argument is not provided, hostname verification is silently skipped. This can lead to scenarios where certificate hostname verification appears to succeed despite misconfiguration, as no ValueError is raised. This issue also affects asyncio.create connection() and asyncio.loop.start tls(). If a server hostname value that is neither an empty string nor None is passed to these APIs, verification proceeds normally.Recommendations
Pass a valid, non-None, and non-empty
server hostname value to SSLContext.wrap bio(), asyncio.create connection(), or asyncio.loop.start tls() to ensure certificate hostname verification is performed.
Update to the latest version of Python to ensure a ValueError is raised when server hostname is missing, preventing silent verification failure.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Python