PT-2026-95548 · Pypi · Anyio

CVE-2026-64847

·

Published

2026-09-18

·

Updated

2026-10-02

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions AnyIO versions prior to 4.14.2
Description AnyIO starts process-pool workers with the standard error stream connected to a pipe that the parent process never drains. Although documentation states all three standard streams are redirected, the worker only redirects stdin and stdout to /dev/null. If worker code writes a significant amount of attacker-influenced data to sys.stderr, the pipe can fill up and block the worker before it returns the standard-output protocol response. This results in the awaiting process-pool call remaining blocked indefinitely, leading to a denial of service. This issue affects applications that execute untrusted or faulty worker code capable of producing substantial standard-error output.
Recommendations Update to version 4.14.2. As a temporary workaround, close sys.stderr in the target function to prevent the deadlock.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-XS44337
CVE-2026-64847
ECHO-B8CF-50B8-5B03
GHSA-5P39-CFHJ-2XMP
PYSEC-2026-4024
SUSE-SU-2026:4416-1

Affected Products

Anyio