PT-2026-103461 · Python · Python

·

CVE-2026-19553

·

Published

2026-09-30

·

Updated

2026-10-02

CVSS v4.0

7.6

High

VectorAV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Python (affected versions not specified)
Description The ssl.SSLContext.wrap bio() function fails to require the server hostname argument to be non-null when ssl.SSLContext.check hostname is enabled. Due to a missing parameter check in SSLObject, if the server hostname argument is not provided, hostname verification is silently skipped. This can lead to scenarios where certificate hostname verification appears to succeed despite misconfiguration, as no ValueError is raised. This issue also affects asyncio.create connection() and asyncio.loop.start tls(). If a server hostname value that is neither an empty string nor None is passed to these APIs, verification proceeds normally.
Recommendations Pass a valid, non-None, and non-empty server hostname value to SSLContext.wrap bio(), asyncio.create connection(), or asyncio.loop.start tls() to ensure certificate hostname verification is performed. Update to the latest version of Python to ensure a ValueError is raised when server hostname is missing, preventing silent verification failure.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19553

Affected Products

Python