PT-2026-95548 · Pypi · Anyio
CVE-2026-64847
·
Published
2026-09-18
·
Updated
2026-10-02
CVSS v4.0
6.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
AnyIO versions prior to 4.14.2
Description
AnyIO starts process-pool workers with the standard error stream connected to a pipe that the parent process never drains. Although documentation states all three standard streams are redirected, the worker only redirects stdin and stdout to /dev/null. If worker code writes a significant amount of attacker-influenced data to
sys.stderr, the pipe can fill up and block the worker before it returns the standard-output protocol response. This results in the awaiting process-pool call remaining blocked indefinitely, leading to a denial of service. This issue affects applications that execute untrusted or faulty worker code capable of producing substantial standard-error output.Recommendations
Update to version 4.14.2.
As a temporary workaround, close
sys.stderr in the target function to prevent the deadlock.Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Anyio