PT-2026-95726 · Pypi · Anyio
CVE-2026-63374
·
Published
2026-09-18
·
Updated
2026-10-03
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
anyio versions prior to 4.14.2
Description
Services using internationalized (non-ASCII) domain names are susceptible to a TLS certificate validation bypass. When using the
connect tcp() function or TLSStream.wrap(), the software mishandles the hostname validation process. If a connection is hijacked and redirected to a malicious server, an attacker can present a legitimate certificate using the IDNA 2003 encoded version of the domain name, which the client will incorrectly validate. IDNA (Internationalizing Domain Names in Applications) is a system that allows non-ASCII characters in domain names. ASCII-only hostnames are not affected.Recommendations
Update to version 4.14.2.
Encode host names via the
idna package prior to connecting.Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Anyio