PT-2026-95726 · Pypi · Anyio

CVE-2026-63374

·

Published

2026-09-18

·

Updated

2026-10-03

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions anyio versions prior to 4.14.2
Description Services using internationalized (non-ASCII) domain names are susceptible to a TLS certificate validation bypass. When using the connect tcp() function or TLSStream.wrap(), the software mishandles the hostname validation process. If a connection is hijacked and redirected to a malicious server, an attacker can present a legitimate certificate using the IDNA 2003 encoded version of the domain name, which the client will incorrectly validate. IDNA (Internationalizing Domain Names in Applications) is a system that allows non-ASCII characters in domain names. ASCII-only hostnames are not affected.
Recommendations Update to version 4.14.2. Encode host names via the idna package prior to connecting.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63374
ECHO-D875-04B9-4F82
GHSA-82R6-8W77-94W6

Affected Products

Anyio